HIGH7.5
GHSA-hpp2-2cr5-pf6g
Denial of service due to unlimited number of parts
Quick fix
GHSA-hpp2-2cr5-pf6g — @fastify/multipart: upgrade to the fixed version with the command below.
npm install @fastify/multipart@6.0.1Details
### Impact
* The multipart body parser accepts an unlimited number of file parts. * The multipart body parser accepts an unlimited number of field parts. * The multipart body parser accepts an unlimited number of empty parts as field parts.
### Patches
This is fixed in v7.4.1 (for Fastify v4.x) and v6.0.1 (for Fastify v3.x).
### Workarounds
There are no known workaround.
### References
Reported at https://hackerone.com/reports/1816195.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/fastify/fastify-multipart/security/advisories/GHSA-hpp2-2cr5-pf6g[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-25576[ADVISORY]
- https://github.com/fastify/fastify-multipart/commit/85be81bedf5b29cfd9fe3efc30fb5a17173c1297[WEB]
- https://hackerone.com/reports/1816195[WEB]
- https://github.com/fastify/fastify-multipart[PACKAGE]
- https://github.com/fastify/fastify-multipart/releases/tag/v6.0.1[WEB]
- https://github.com/fastify/fastify-multipart/releases/tag/v7.4.1[WEB]