@fastify/multipart@7.4.0 vulnerabilities

Multipart plugin for Fastify

Direct Vulnerabilities

Known vulnerabilities in the @fastify/multipart package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Denial of Service (DoS)

@fastify/multipart is a Multipart plugin for Fastify

Affected versions of this package are vulnerable to Denial of Service (DoS) via the fastifyMultipart function, when the multipart body parser accepts an unlimited number of file and field parts or empty parts.

How to fix Denial of Service (DoS)?

Upgrade @fastify/multipart to version 6.0.1, 7.4.1 or higher.

<6.0.1 >=7.0.0 <7.4.1