LOW
GHSA-q3w9-g74q-vp5f
Denial of Service in express-fileupload
Quick fix
GHSA-q3w9-g74q-vp5f — express-fileupload: upgrade to the fixed version with the command below.
npm install express-fileupload@1.1.6-alpha.6Details
Versions of `express-fileupload` prior to 1.1.6-alpha.6 are vulnerable to Denial of Service. The package causes server responses to be delayed (up to 30s in internal testing) if the request contains a large `filename` of `.` characters.
## Recommendation
Upgrade to version 1.1.6-alpha.6 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/express-fileupload
Introduced in:
0Fixed in: 1.1.6-alpha.6Fix
npm install express-fileupload@1.1.6-alpha.6npm/express-fileupload
Introduced in:
0Fixed in: 1.1.6-alpha.6Fix
npm install express-fileupload@1.1.6-alpha.6npm/express-fileupload
Introduced in:
0Fixed in: 1.1.6-alpha.6Fix
npm install express-fileupload@1.1.6-alpha.6npm/express-fileupload
Introduced in:
0Fixed in: 1.1.6-alpha.6Fix
npm install express-fileupload@1.1.6-alpha.6npm/express-fileupload
Introduced in:
0Fixed in: 1.1.6-alpha.6Fix
npm install express-fileupload@1.1.6-alpha.6