The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.
Start learningUpgrade multiparty to version 4.3.1 or higher.
multiparty is a multipart/form-data parser which supports streaming
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in its part header handling, which bounds accumulated field values and file sizes but places no limit on the size of an individual part's headers. An attacker can exhaust server memory and crash the process with a single request by sending a multipart/form-data body whose part header never terminates. This requires only that the service accept multipart uploads through this parser, and the documented field and file size limits do not constrain the header accumulation.