Allocation of Resources Without Limits or Throttling Affecting multiparty package, versions >=2.1.0 <4.3.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-MULTIPARTY-19784399
  • published14 Sept 2026
  • disclosed11 Sept 2026
  • creditiRevivalx

Introduced: 11 Sep 2026

NewCVE-2026-87908  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade multiparty to version 4.3.1 or higher.

Overview

multiparty is a multipart/form-data parser which supports streaming

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in its part header handling, which bounds accumulated field values and file sizes but places no limit on the size of an individual part's headers. An attacker can exhaust server memory and crash the process with a single request by sending a multipart/form-data body whose part header never terminates. This requires only that the service accept multipart uploads through this parser, and the documented field and file size limits do not constrain the header accumulation.

CVSS Base Scores

version 4.0
version 3.1