Your message dated Sun, 13 Sep 2026 09:05:34 +0000
with message-id <[email protected]>
and subject line Bug#1147414: fixed in node-multiparty 4.3.1+~4.2.1-1
has caused the Debian Bug report #1147414,
regarding node-multiparty: CVE-2026-87908
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1147414: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147414
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-multiparty
Version: 4.3.0+~4.2.1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for node-multiparty.
CVE-2026-87908[0]:
| multiparty is a Node.js library for parsing multipart/form-data
| request bodies. In versions from 2.1.0 up to but not including
| 4.3.1, the parser does not bound the amount of memory used while
| accumulating the headers of a single multipart part. An
| unauthenticated attacker can send a single request whose part
| carries a very large volume of header bytes, forcing the parser to
| buffer all of them and exhausting the process memory, which crashes
| the server. This is a denial of service with no confidentiality or
| integrity impact. The issue is fixed in multiparty 4.3.1, which caps
| the size of the accumulated part headers. Users should upgrade to
| multiparty 4.3.1 or later.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-87908
https://www.cve.org/CVERecord?id=CVE-2026-87908
[1]
https://github.com/pillarjs/multiparty/security/advisories/GHSA-5h46-2939-q3wh
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: node-multiparty
Source-Version: 4.3.1+~4.2.1-1
Done: Xavier Guimard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
node-multiparty, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-multiparty package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 13 Sep 2026 10:51:31 +0200
Source: node-multiparty
Architecture: source
Version: 4.3.1+~4.2.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1147414
Changes:
node-multiparty (4.3.1+~4.2.1-1) unstable; urgency=medium
.
* Team upload
* New upstream version (Closes: #1147414, CVE-2026-87908)
* Unfuzz patches
Checksums-Sha1:
cd5e3f1d7fc302d82a430e687f848a40d0a5a435 2737
node-multiparty_4.3.1+~4.2.1-1.dsc
221556ebed5aee738b60e55c836362fb7a02868e 2730
node-multiparty_4.3.1+~4.2.1.orig-types-multiparty.tar.gz
452cb417549984d196d070f8cefd5082867f9b6b 802284
node-multiparty_4.3.1+~4.2.1.orig.tar.gz
e85c3ceec1923e1c675da523a0cb71fa1bde1a53 4804
node-multiparty_4.3.1+~4.2.1-1.debian.tar.xz
Checksums-Sha256:
f88f3e007a83ee05eb8d39926baf80722b1176eb2b02ce6cb2a655f676f5dd38 2737
node-multiparty_4.3.1+~4.2.1-1.dsc
a43698d1d662a61edc31c82af78b126b543f0bac586eb654a4deb3be0f1eb8da 2730
node-multiparty_4.3.1+~4.2.1.orig-types-multiparty.tar.gz
e179dbda43e6f604270d4a10a4a0a761cfd7a308c58dbcb336f2f75578f77a8b 802284
node-multiparty_4.3.1+~4.2.1.orig.tar.gz
0d9e427e5465245e79e532a8238a407fcb53e4cbf41eb4d349a687ae535e8305 4804
node-multiparty_4.3.1+~4.2.1-1.debian.tar.xz
Files:
dcc5319c1485219fa91f7af893375ff5 2737 javascript optional
node-multiparty_4.3.1+~4.2.1-1.dsc
816f11c5e1cdcb89a0581f7beebc5479 2730 javascript optional
node-multiparty_4.3.1+~4.2.1.orig-types-multiparty.tar.gz
0e5028908d1b64e8c085bc51396ee509 802284 javascript optional
node-multiparty_4.3.1+~4.2.1.orig.tar.gz
6a437bac0001f93c8ecc891bf01a38b0 4804 javascript optional
node-multiparty_4.3.1+~4.2.1-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqmZE8ACgkQ9tdMp8mZ
7uliuQ/+ISeAam7rUJ6M0/UwX1kix+NzR2Tlg9+Lna5KoNgRQEWk7wJJB0e3ojSU
xsxxj4u6aqLb6UnVIdaWuvBBAFuphJUStiIvjR4VVjJ6lOslD1XmvzQ/+luaFA0I
o3y8sl06eVsdEEoUtHWKrFJshvh7EFR6XN4B3l61YVwZFXI5pH6X7hJqzkfFgd1y
KGfmtFNM7MvrWmZSLZkxiRaqAo+FV/W1PEJyffUTUkGs9wN3EfGz0KCpW+9zecEg
YKShmhUsfm7ZmCA+3BEVhhsM6C5U4LIW5I90S0yxJRd6xr3l8ovjMUeYkAVkKe2e
c2hJwO5hKSWaQBs/qSUV0nhxuSc0hnMVpyDCJfD2hrigR+10aWcAZ85JCkKMTh+k
EMseHO+PWKHxOdcyGoOcmo0kiKOJsM0Wi4k5qwW5MGZuNtgXgsEcWSLI52iNqznJ
xYWe6S6jPqlcFCG8ashy2NXqJHY4XRJHTzYp7zjnq8yjtAN06JBjxDi7KZE64R7T
/ivyud2O5ZC8vbeIhy6ok9Cwq/sBCl3/i6tfZDxcpAgCBBw1LURo+veL5aSg0W0y
fOJ5v31HtSfVnXJc5HC3wgHA8V3d1Z6FE6atM/ikAki0QMeWtJsa3+Giw/qgvp2o
DGc5il2GBIb2k5YMZtw+dErPTSVwMBxmhJofE5wbGGitWvYsqbY=
=m1E/
-----END PGP SIGNATURE-----
pgpZzx1Nk75M4.pgp
Description: PGP signature
--- End Message ---
--
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel