#1147414 node-multiparty: CVE-2026-87908

Package:
src:node-multiparty
Source:
src:node-multiparty
Submitter:
Salvatore Bonaccorso
Date:
2026-09-13 09:07:02 UTC
Severity:
normal
Tags:
#1147414#5
Date:
2026-09-11 15:24:47 UTC
From:
To:
Hi,

The following vulnerability was published for node-multiparty.

CVE-2026-87908[0]:
| multiparty is a Node.js library for parsing multipart/form-data
| request bodies. In versions from 2.1.0 up to but not including
| 4.3.1, the parser does not bound the amount of memory used while
| accumulating the headers of a single multipart part. An
| unauthenticated attacker can send a single request whose part
| carries a very large volume of header bytes, forcing the parser to
| buffer all of them and exhausting the process memory, which crashes
| the server. This is a denial of service with no confidentiality or
| integrity impact. The issue is fixed in multiparty 4.3.1, which caps
| the size of the accumulated part headers. Users should upgrade to
| multiparty 4.3.1 or later.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-87908
https://www.cve.org/CVERecord?id=CVE-2026-87908
[1] https://github.com/pillarjs/multiparty/security/advisories/GHSA-5h46-2939-q3wh

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1147414#8
Date:
2026-09-13 08:54:56 UTC
From:
To:
Hello,

Bug #1147414 in node-multiparty reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-multiparty/-/commit/654a912ca70a13376e64192a92d32f05f3232dd6

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1147414

#1147414#13
Date:
2026-09-13 08:54:55 UTC
From:
To:
Hello,

Bug #1147414 in node-multiparty reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-multiparty/-/commit/654a912ca70a13376e64192a92d32f05f3232dd6

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1147414

#1147414#18
Date:
2026-09-13 09:05:34 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
node-multiparty, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147414@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-multiparty package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 13 Sep 2026 10:51:31 +0200
Source: node-multiparty
Architecture: source
Version: 4.3.1+~4.2.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1147414
Changes:
 node-multiparty (4.3.1+~4.2.1-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream version (Closes: #1147414, CVE-2026-87908)
   * Unfuzz patches
Checksums-Sha1:
 cd5e3f1d7fc302d82a430e687f848a40d0a5a435 2737 node-multiparty_4.3.1+~4.2.1-1.dsc
 221556ebed5aee738b60e55c836362fb7a02868e 2730 node-multiparty_4.3.1+~4.2.1.orig-types-multiparty.tar.gz
 452cb417549984d196d070f8cefd5082867f9b6b 802284 node-multiparty_4.3.1+~4.2.1.orig.tar.gz
 e85c3ceec1923e1c675da523a0cb71fa1bde1a53 4804 node-multiparty_4.3.1+~4.2.1-1.debian.tar.xz
Checksums-Sha256:
 f88f3e007a83ee05eb8d39926baf80722b1176eb2b02ce6cb2a655f676f5dd38 2737 node-multiparty_4.3.1+~4.2.1-1.dsc
 a43698d1d662a61edc31c82af78b126b543f0bac586eb654a4deb3be0f1eb8da 2730 node-multiparty_4.3.1+~4.2.1.orig-types-multiparty.tar.gz
 e179dbda43e6f604270d4a10a4a0a761cfd7a308c58dbcb336f2f75578f77a8b 802284 node-multiparty_4.3.1+~4.2.1.orig.tar.gz
 0d9e427e5465245e79e532a8238a407fcb53e4cbf41eb4d349a687ae535e8305 4804 node-multiparty_4.3.1+~4.2.1-1.debian.tar.xz
Files:
 dcc5319c1485219fa91f7af893375ff5 2737 javascript optional node-multiparty_4.3.1+~4.2.1-1.dsc
 816f11c5e1cdcb89a0581f7beebc5479 2730 javascript optional node-multiparty_4.3.1+~4.2.1.orig-types-multiparty.tar.gz
 0e5028908d1b64e8c085bc51396ee509 802284 javascript optional node-multiparty_4.3.1+~4.2.1.orig.tar.gz
 6a437bac0001f93c8ecc891bf01a38b0 4804 javascript optional node-multiparty_4.3.1+~4.2.1-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqmZE8ACgkQ9tdMp8mZ
7uliuQ/+ISeAam7rUJ6M0/UwX1kix+NzR2Tlg9+Lna5KoNgRQEWk7wJJB0e3ojSU
xsxxj4u6aqLb6UnVIdaWuvBBAFuphJUStiIvjR4VVjJ6lOslD1XmvzQ/+luaFA0I
o3y8sl06eVsdEEoUtHWKrFJshvh7EFR6XN4B3l61YVwZFXI5pH6X7hJqzkfFgd1y
KGfmtFNM7MvrWmZSLZkxiRaqAo+FV/W1PEJyffUTUkGs9wN3EfGz0KCpW+9zecEg
YKShmhUsfm7ZmCA+3BEVhhsM6C5U4LIW5I90S0yxJRd6xr3l8ovjMUeYkAVkKe2e
c2hJwO5hKSWaQBs/qSUV0nhxuSc0hnMVpyDCJfD2hrigR+10aWcAZ85JCkKMTh+k
EMseHO+PWKHxOdcyGoOcmo0kiKOJsM0Wi4k5qwW5MGZuNtgXgsEcWSLI52iNqznJ
xYWe6S6jPqlcFCG8ashy2NXqJHY4XRJHTzYp7zjnq8yjtAN06JBjxDi7KZE64R7T
/ivyud2O5ZC8vbeIhy6ok9Cwq/sBCl3/i6tfZDxcpAgCBBw1LURo+veL5aSg0W0y
fOJ5v31HtSfVnXJc5HC3wgHA8V3d1Z6FE6atM/ikAki0QMeWtJsa3+Giw/qgvp2o
DGc5il2GBIb2k5YMZtw+dErPTSVwMBxmhJofE5wbGGitWvYsqbY=
=m1E/
-----END PGP SIGNATURE-----