← Vulnerability feed

Vulnerability record · CVE-2019-5097 · published 3 December 2019

CVE-2019-5097: GoAhead web server multipart/form-data request infinite loop DoS

Embedthis · Goahead

The base GoAhead web server (v5.0.1, v4.1.1, v3.6.5) enters an infinite loop while processing specially crafted multipart/form-data requests. Because the request can be unauthenticated and the target resource need not exist, any reachable server instance is exposed to a trivial remote denial of service.

7.5 CVSS 3.1 High EPSS 45% · top 1.3% CWE-835 · CWE-835
7.5CVSS 3.1 base score, v2 5.0
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to an infinite loop in the process. The request can be unauthenticated in the form of GET or POST requests and does not require the requested resource to exist on the server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityUnauthenticated remote denial of service with low attack complexity and a high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

The base GoAhead web server (v5.0.1, v4.1.1, v3.6.5) enters an infinite loop while processing specially crafted multipart/form-data requests. Because the request can be unauthenticated and the target resource need not exist, any reachable server instance is exposed to a trivial remote denial of service.

Impact

An attacker can hang the server process, denying service to legitimate users; no data confidentiality or integrity impact is described.

Attack surface

Reachable over the network via HTTP GET or POST requests to the web server; no authentication and no user interaction are required, and the requested resource does not need to exist.

Exploitation

Not listed in CISA KEV and no ransomware use is documented, but the reference is tagged Exploit and EPSS is 0.45 (98.7th percentile), indicating meaningful likelihood of exploitation.

What to do

  • Upgrade GoAhead to a version later than v5.0.1, v4.1.1 or v3.6.5 that contains the fix; verify the vendor advisory for the corrected release.
  • If immediate upgrade is not possible, restrict network access to the GoAhead listener with firewall rules or a reverse proxy that filters malformed multipart/form-data requests.
  • Enforce request size and multipart parsing limits at the front-end proxy to reject oversized or malformed bodies before they reach GoAhead.
  • Monitor the GoAhead process for CPU saturation and restart it automatically if it becomes unresponsive.

Detection

  • Alert on sustained high CPU or unresponsive GoAhead processes correlated with inbound multipart/form-data requests.
  • Log and inspect HTTP requests with multipart/form-data content types, especially those targeting non-existent resources or with malformed boundaries.
  • Track repeated GET/POST requests from a single source that precede a service hang or restart.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-5097 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2017-17562Embedthis GoAhead CGI environment variable injection enables remote code executionEmbedthis GoAhead before 3.6.5 initializes the environment of forked CGI scripts using untrusted HTTP request parameters in cgiHandler in cgi.c. When…KEVEPSS 96%analysed9.8CVE-2021-41615Embedthis goahead vulnerabilitywebsda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise valu…EPSS 1.4%9.8CVE-2021-43298Embedthis goahead improper restriction of authentication attempts vulnerabilityThe code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This me…EPSS 2.3%9.8CVE-2021-42342GoAhead file upload filter allows environment variable injection into CGI scriptsGoAhead 4.x and 5.x before 5.1.5 fail to prefix user form variables with the CGI prefix in the file upload filter, letting untrusted environment vari…EPSS 59%analysed9.8CVE-2019-5096GoAhead web server use-after-free in multipart/form-data handlingGoAhead versions 5.0.1, 4.1.1 and 3.6.5 contain a use-after-free when processing multipart/form-data requests. A crafted HTTP request corrupts heap s…EPSS 67%analysed9.8CVE-2017-1000471Embedthis goahead null pointer dereference vulnerabilityEmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of …EPSS 8.6%9.8CVE-2017-5674Embedthis goahead information exposure vulnerabilityA vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft …EPSS 22%8.8CVE-2020-15688Embedthis goahead authentication bypass by capture-replay vulnerabilityThe HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthentica…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2019-5097), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.