Multiparty Denial-of-Service Vulnerability via Uncaught Exception in Filename Parameter Parsing

Vulnerability

A denial-of-service vulnerability has been identified in the multiparty package, specifically in versions through 4.2.3. The issue arises when the parser processes a multipart/form-data request with a Content-Disposition header that includes a malformed percent-encoding in the filename parameter. This improper encoding leads to a URIError, which is not caught and causes the process to crash. Any service that accepts multipart uploads using multiparty is susceptible to this vulnerability.

Impact

Exploitation of this vulnerability causes the process to crash, leading to a denial-of-service condition.

Remediation

Users are advised to upgrade to multiparty version 4.3.0 or higher.

Added: May 12, 2026, 10:19 AM
Updated: May 12, 2026, 10:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
8.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.