diff --git a/advisories/github-reviewed/2025/05/GHSA-4pg4-qvpc-4q3h/GHSA-4pg4-qvpc-4q3h.json b/advisories/github-reviewed/2025/05/GHSA-4pg4-qvpc-4q3h/GHSA-4pg4-qvpc-4q3h.json new file mode 100644 index 00000000000..42f2006a5f9 --- /dev/null +++ b/advisories/github-reviewed/2025/05/GHSA-4pg4-qvpc-4q3h/GHSA-4pg4-qvpc-4q3h.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pg4-qvpc-4q3h", + "modified": "2025-05-19T22:16:30Z", + "published": "2025-05-19T22:16:30Z", + "aliases": [ + "CVE-2025-47944" + ], + "summary": "Multer vulnerable to Denial of Service from maliciously crafted requests", + "details": "### Impact\nA vulnerability in Multer versions >=1.4.4-lts.1 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed multi-part upload request. This request causes an unhandled exception, leading to a crash of the process.\n\n### Patches\nUsers should upgrade to `2.0.0`\n\n### Workarounds\nNone\n\n### References\n\n- https://github.com/expressjs/multer/issues/1176\n- https://github.com/expressjs/multer/commit/2c8505f207d923dd8de13a9f93a4563e59933665", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "multer" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4.4-lts.1" + }, + { + "fixed": "2.0.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/expressjs/multer/security/advisories/GHSA-4pg4-qvpc-4q3h" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47944" + }, + { + "type": "WEB", + "url": "https://github.com/expressjs/multer/issues/1176" + }, + { + "type": "WEB", + "url": "https://github.com/expressjs/multer/commit/2c8505f207d923dd8de13a9f93a4563e59933665" + }, + { + "type": "PACKAGE", + "url": "https://github.com/expressjs/multer" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-05-19T22:16:30Z", + "nvd_published_at": "2025-05-19T20:15:26Z" + } +} \ No newline at end of file