Vulnerability record · CVE-2019-5096 · published 3 December 2019
CVE-2019-5096: GoAhead web server use-after-free in multipart/form-data handling
Embedthis · Goahead
GoAhead versions 5.0.1, 4.1.1 and 3.6.5 contain a use-after-free when processing multipart/form-data requests. A crafted HTTP request corrupts heap structures and can lead to full code execution. The flaw is remotely reachable without authentication and does not require the requested resource to exist.
Description
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the processing of this request that can be used to corrupt heap structures that could lead to full code execution. The request can be unauthenticated in the form of GET or POST requests, and does not require the requested resource to exist on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 3.1 base score is 9.8 with network reachability, no privileges and no user interaction, and a public exploit reference exists.
What it is
GoAhead versions 5.0.1, 4.1.1 and 3.6.5 contain a use-after-free when processing multipart/form-data requests. A crafted HTTP request corrupts heap structures and can lead to full code execution. The flaw is remotely reachable without authentication and does not require the requested resource to exist.
Impact
An unauthenticated attacker can corrupt heap memory and potentially execute arbitrary code in the context of the GoAhead server process, gaining full control of the affected service.
Attack surface
Reachable over the network via HTTP GET or POST requests carrying multipart/form-data content; no authentication and no user interaction are required, and the target resource need not exist.
Exploitation
Not listed in CISA KEV, but EPSS is 0.66982 (99.26th percentile) and the only references are Talos advisories tagged Exploit, indicating public exploit detail exists. No confirmed in-the-wild exploitation is stated in the record.
What to do
- Upgrade GoAhead to a release later than 5.0.1, 4.1.1 and 3.6.5 that contains the fix; verify the vendor advisory for the exact patched version.
- If patching is not immediately possible, restrict network access to the GoAhead service and place it behind an authenticating reverse proxy.
- Disable or reject multipart/form-data processing where the application does not require file uploads.
- Monitor and rate-limit HTTP requests to the GoAhead listener to reduce exposure to crafted multipart requests.
- Inventory all embedded GoAhead instances, since the server is often bundled in IoT and appliance firmware.
Detection
- Inspect HTTP request logs for multipart/form-data requests to non-existent or unexpected paths, especially GET requests with multipart bodies.
- Monitor GoAhead processes for crashes, restarts or abnormal memory behavior that may indicate heap corruption attempts.
- Use network detection to flag malformed or oversized multipart/form-data requests targeting GoAhead endpoints.
- Correlate repeated unauthenticated multipart requests from a single source as a possible exploitation attempt.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2019-0888 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2019-0888 | ExploitThird Party Advisory |
Track CVE-2019-5096 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-5096), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.