VDB
Sign up
HIGH7.5

GHSA-p9f8-gqjf-m75j

Uncontrolled Resource Consumption in fastify-multipart

Quick fix

GHSA-p9f8-gqjf-m75j — fastify-multipart: upgrade to the fixed version with the command below.

npm install fastify-multipart@1.0.5

Details

Prototype pollution vulnerability in `fastify-multipart` < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests by sending a specially crafted request.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/fastify-multipart
Introduced in: 0Fixed in: 1.0.5
Fixnpm install fastify-multipart@1.0.5

References