Junglewise Threat Intelligence

CVE-2020-8136: fastify-multipart prototype pollution denial of service

CVE-2020-8136 · Severity: low · CVSS 3.1 · Published 2021-05-06

Vendors: npm, Fastify.

Executive brief

fastify-multipart is a widely-used Node.js library that handles file uploads in Fastify web applications. A prototype pollution vulnerability allows attackers to crash applications by sending a specially crafted multipart request, causing denial of service and service unavailability.

Technical details

This is a prototype pollution vulnerability (CWE-400: Uncontrolled Resource Consumption) in fastify-multipart versions before 1.0.5. The vulnerability is exploited by sending a specially crafted multipart request to applications using the affected library. An attacker with network access can trigger the vulnerability without authentication or user interaction. Successful exploitation results in application crash and denial of service. The vulnerability is fixed in version 1.0.5 and later.

Affected products

  • Fastify fastify-multipart < 1.0.5

Timeline

  • 2020-03-20: disclosed: Published on NVD
  • 2020: patched: Fixed in version 1.0.5
  • 2021-05-06: advisory: GitHub Security Advisory published

References

Related threats