Impact
multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field name that collides with an inherited Object.prototype property (e.g., __proto__, constructor, toString), the parser invokes .push() on the inherited prototype value rather than an array, throwing a TypeError that propagates as an uncaught exception and crashes the process. Any service accepting multipart uploads via multiparty is affected.
Patches
Users should upgrade to multiparty@4.3.0 or higher.
Workarounds
None.
Impact
multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a
multipart/form-datarequest with a field name that collides with an inheritedObject.prototypeproperty (e.g.,__proto__,constructor,toString), the parser invokes.push()on the inherited prototype value rather than an array, throwing aTypeErrorthat propagates as an uncaught exception and crashes the process. Any service accepting multipart uploads via multiparty is affected.Patches
Users should upgrade to multiparty@4.3.0 or higher.
Workarounds
None.