Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.51% | — | Pillarjs MultipartyAI | 11/9/2026 | 16/9/2026 | multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can send a single request whose part carries a… | |
| Analizada | Alta (7.5) | 0.49% | — | Fastify-multipart | 15/8/2026 | 2/9/2026 | @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing between multipart parts. The iterator rejection that occurs between parts… | |
| Analizada | Alta (7.5) | 0.60% | — | Fastify-multipart | 15/8/2026 | 2/9/2026 | @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the client then aborts the connection before… | |
| Analizada | Baja (3.7) | 0.34% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a… | |
| Analizada | Alta (7.5) | 0.46% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to… | |
| Analizada | Baja (3.7) | 0.26% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator.… | |
| Analizada | Media (5.3) | 0.29% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the… | |
| Aplazada | Alta (7.5) | 0.85% | — | Python MultipartAI | 13/5/2026 | 7/8/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An… | |
| Analizada | Alta (7.5) | 0.58% | — | Pillarjs Multiparty | 12/5/2026 | 17/6/2026 | multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose filename* parameter contains a malformed percent-encoding, the parser invokes decodeURI on the value without try/catch. The resulting URIError… | |
| Analizada | Alta (7.5) | 0.53% | — | Pillarjs Multiparty | 12/5/2026 | 17/6/2026 | multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field name that collides with an inherited Object.prototype property such as __proto__, constructor, or toString, the parser invokes .push() on the inherited prototype value… | |
| Analizada | Alta (7.5) | 0.62% | — | Pillarjs Multiparty | 12/5/2026 | 17/6/2026 | multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename parameter parser. A crafted multipart upload with a long header value can cause regex matching to take seconds, blocking the event loop. Impact: any service accepting… | |
| Analizada | Media (5.3) | 0.42% | — | Fastapiexpert Python-multipart | 18/4/2026 | 17/6/2026 | Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing… | |
| Aplazada | Alta (7.5) | 1.0% | — | Konghq MultipartAI | 12/3/2026 | 24/8/2026 | multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential backtracking (ReDoS) when parsing maliciously crafted HTTP or multipart segment… | |
| Modificada | Alta (7.5) | 2.2% | — | Fastapiexpert Python-multipart | 27/1/2026 | 7/8/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious… | |
| Aplazada | Alta (7.5) | 0.57% | — | Fastify MultipartAI | 23/1/2025 | 17/6/2026 | @fastify/multipart is a Fastify plugin for parsing the multipart content-type. Prior to versions 8.3.1 and 9.0.3, the `saveRequestFiles` function does not delete the uploaded temporary files when user cancels the request. The issue is fixed in versions 8.3.1 and 9.0.3. As a workaround, do not use `saveRequestFiles`. | |
| Aplazada | Alta (7.5) | 0.64% | — | Fastapiexpert Python-multipartAI | 2/12/2024 | 17/6/2026 | python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks (CR \r or LF \n) in front of the first boundary and any tailing bytes after the last boundary. This happens one byte at a time and emits a log event each time, which may cause excessive logging for… | |
| Analizada | Alta (7.5) | 1.5% | — | Fastapiexpert Python-multipart | 5/2/2024 | 17/6/2026 | `python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. An attacker could send a custom-made `Content-Type` option that is very difficult for the RegEx to process, consuming CPU… | |
| Modificada | Alta (7.5) | 1.5% | — | Fastify-multipart | 14/2/2023 | 17/6/2026 | @fastify/multipart is a Fastify plugin to parse the multipart content-type. Prior to versions 7.4.1 and 6.0.1, @fastify/multipart may experience denial of service due to a number of situations in which an unlimited number of parts are accepted. This includes the multipart body parser accepting an unlimited number of… | |
| Modificada | Alta (7.5) | 0.92% | — | Konghq Multipart | 12/2/2023 | 17/6/2026 | A vulnerability was found in Kong lua-multipart 0.5.8-1. It has been declared as problematic. This vulnerability affects the function is_header of the file src/multipart.lua. The manipulation leads to inefficient regular expression complexity. Upgrading to version 0.5.9-1 is able to address this issue. The patch is… | |
| Modificada | Alta (7.8) | 1.3% | — | Connect-multiparty Project Connect-multiparty | 16/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report. | |
| Modificada | Alta (7.5) | 2.0% | — | Fastify-multipart | 11/2/2022 | 17/6/2026 | This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible to crash the application. **Note:** This is a bypass of CVE-2020-8136 (https://security.snyk.io/vuln/SNYK-JS-FASTIFYMULTIPART-1290382). | |
| Modificada | Alta (7.5) | 1.5% | — | Fastify-multipart | 20/3/2020 | 17/6/2026 | Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests by sending a specially crafted request. | |
| Modificada | Alta (7.5) | 1.4% | — | Aws-lambda-multipart-parser Project Aws-lambda-multipart-parser | 4/3/2018 | 17/6/2026 | index.js in the Anton Myshenin aws-lambda-multipart-parser NPM package before 0.1.2 has a Regular Expression Denial of Service (ReDoS) issue via a crafted multipart/form-data boundary string. |