Denial of Service in express-fileupload
Low severity
GitHub Reviewed
Published
Sep 3, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
< 1.1.6-alpha.6
<= 1.1.3-alpha.2
<= 1.1.2-alpha.1
<= 1.1.1-alpha.3
<= 1.0.0-alpha.1
Patched versions
1.1.6-alpha.6
1.1.6-alpha.6
1.1.6-alpha.6
1.1.6-alpha.6
1.1.6-alpha.6
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 3, 2020
Last updated
Jan 9, 2023
Versions of
express-fileupload
prior to 1.1.6-alpha.6 are vulnerable to Denial of Service. The package causes server responses to be delayed (up to 30s in internal testing) if the request contains a largefilename
of.
characters.Recommendation
Upgrade to version 1.1.6-alpha.6 or later.
References