← Vulnerability feed

Vulnerability record · CVE-2019-5096 · published 3 December 2019

CVE-2019-5096: GoAhead web server use-after-free in multipart/form-data handling

Embedthis · Goahead

GoAhead versions 5.0.1, 4.1.1 and 3.6.5 contain a use-after-free when processing multipart/form-data requests. A crafted HTTP request corrupts heap structures and can lead to full code execution. The flaw is remotely reachable without authentication and does not require the requested resource to exist.

9.8 CVSS 3.1 Critical EPSS 67% · top 0.7% CWE-416 · Use after free
9.8CVSS 3.1 base score, v2 7.5
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the processing of this request that can be used to corrupt heap structures that could lead to full code execution. The request can be unauthenticated in the form of GET or POST requests, and does not require the requested resource to exist on the server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 3.1 base score is 9.8 with network reachability, no privileges and no user interaction, and a public exploit reference exists.

What it is

GoAhead versions 5.0.1, 4.1.1 and 3.6.5 contain a use-after-free when processing multipart/form-data requests. A crafted HTTP request corrupts heap structures and can lead to full code execution. The flaw is remotely reachable without authentication and does not require the requested resource to exist.

Impact

An unauthenticated attacker can corrupt heap memory and potentially execute arbitrary code in the context of the GoAhead server process, gaining full control of the affected service.

Attack surface

Reachable over the network via HTTP GET or POST requests carrying multipart/form-data content; no authentication and no user interaction are required, and the target resource need not exist.

Exploitation

Not listed in CISA KEV, but EPSS is 0.66982 (99.26th percentile) and the only references are Talos advisories tagged Exploit, indicating public exploit detail exists. No confirmed in-the-wild exploitation is stated in the record.

What to do

  • Upgrade GoAhead to a release later than 5.0.1, 4.1.1 and 3.6.5 that contains the fix; verify the vendor advisory for the exact patched version.
  • If patching is not immediately possible, restrict network access to the GoAhead service and place it behind an authenticating reverse proxy.
  • Disable or reject multipart/form-data processing where the application does not require file uploads.
  • Monitor and rate-limit HTTP requests to the GoAhead listener to reduce exposure to crafted multipart requests.
  • Inventory all embedded GoAhead instances, since the server is often bundled in IoT and appliance firmware.

Detection

  • Inspect HTTP request logs for multipart/form-data requests to non-existent or unexpected paths, especially GET requests with multipart bodies.
  • Monitor GoAhead processes for crashes, restarts or abnormal memory behavior that may indicate heap corruption attempts.
  • Use network detection to flag malformed or oversized multipart/form-data requests targeting GoAhead endpoints.
  • Correlate repeated unauthenticated multipart requests from a single source as a possible exploitation attempt.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-5096 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-17562Embedthis GoAhead CGI environment variable injection enables remote code executionEmbedthis GoAhead before 3.6.5 initializes the environment of forked CGI scripts using untrusted HTTP request parameters in cgiHandler in cgi.c. When…KEVEPSS 96%analysed9.8CVE-2021-41615Embedthis goahead vulnerabilitywebsda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise valu…EPSS 1.4%9.8CVE-2021-43298Embedthis goahead improper restriction of authentication attempts vulnerabilityThe code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This me…EPSS 2.3%9.8CVE-2021-42342GoAhead file upload filter allows environment variable injection into CGI scriptsGoAhead 4.x and 5.x before 5.1.5 fail to prefix user form variables with the CGI prefix in the file upload filter, letting untrusted environment vari…EPSS 59%analysed9.8CVE-2017-1000471Embedthis goahead null pointer dereference vulnerabilityEmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of …EPSS 8.6%9.8CVE-2017-5674Embedthis goahead information exposure vulnerabilityA vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft …EPSS 22%8.8CVE-2020-15688Embedthis goahead authentication bypass by capture-replay vulnerabilityThe HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthentica…EPSS 4.0%8.8CVE-2017-5675Embedthis goahead command injection vulnerabilityA command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2019-5096), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.