VDB
Sign up
LOW

GHSA-q3w9-g74q-vp5f

Denial of Service in express-fileupload

Quick fix

GHSA-q3w9-g74q-vp5f — express-fileupload: upgrade to the fixed version with the command below.

npm install express-fileupload@1.1.6-alpha.6

Details

Versions of `express-fileupload` prior to 1.1.6-alpha.6 are vulnerable to Denial of Service. The package causes server responses to be delayed (up to 30s in internal testing) if the request contains a large `filename` of `.` characters.

## Recommendation

Upgrade to version 1.1.6-alpha.6 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/express-fileupload
Introduced in: 0Fixed in: 1.1.6-alpha.6
Fixnpm install express-fileupload@1.1.6-alpha.6
npm/express-fileupload
Introduced in: 0Fixed in: 1.1.6-alpha.6
Fixnpm install express-fileupload@1.1.6-alpha.6
npm/express-fileupload
Introduced in: 0Fixed in: 1.1.6-alpha.6
Fixnpm install express-fileupload@1.1.6-alpha.6
npm/express-fileupload
Introduced in: 0Fixed in: 1.1.6-alpha.6
Fixnpm install express-fileupload@1.1.6-alpha.6
npm/express-fileupload
Introduced in: 0Fixed in: 1.1.6-alpha.6
Fixnpm install express-fileupload@1.1.6-alpha.6

References