multiparty vulnerable to Denial of Service via Prototype Pollution leading to Uncaught Exception
Published May 12, 2026
7.5
HIGHCVSS 3.1
EPSS 0.53%
Description
multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field name that collides with an inherited Object.prototype property such as __proto__, constructor, or toString, the parser invokes .push() on the inherited prototype value rather than an array, throwing a TypeError that propagates as an uncaught exception and crashes the process. Impact: any service accepting multipart uploads via multiparty is affected. Workarounds: none. Upgrade to multiparty@4.3.0 or higher.
Affected products
-
- Version 0StatusaffectedConstraints<=4.2.3
- Version 4.3.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Multiparty | Multiparty | unaffected |
|
- < 4.3.0
No data.
No Red Hat product state for this CVE.
multiparty
npm
Introduced 0 Fixed 4.3.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | multiparty | 0 | 4.3.0 |
Remediation
No remediation recorded yet.
References (6)
- https://cna.openjsf.org/security-advisories.html Third Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-29440 Advisory
- https://github.com/advisories/GHSA-qxch-whhj-8956 Advisory
- https://github.com/pillarjs/multiparty/releases/tag/v4.3.0
- https://github.com/pillarjs/multiparty/security/advisories/GHSA-qxch-whhj-8956 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-8161
Change history (0)
No recorded changes yet.