Vulnerability record · CVE-2019-5097 · published 3 December 2019
CVE-2019-5097: GoAhead web server multipart/form-data request infinite loop DoS
Embedthis · Goahead
The base GoAhead web server (v5.0.1, v4.1.1, v3.6.5) enters an infinite loop while processing specially crafted multipart/form-data requests. Because the request can be unauthenticated and the target resource need not exist, any reachable server instance is exposed to a trivial remote denial of service.
Description
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to an infinite loop in the process. The request can be unauthenticated in the form of GET or POST requests and does not require the requested resource to exist on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote denial of service with low attack complexity and a high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
The base GoAhead web server (v5.0.1, v4.1.1, v3.6.5) enters an infinite loop while processing specially crafted multipart/form-data requests. Because the request can be unauthenticated and the target resource need not exist, any reachable server instance is exposed to a trivial remote denial of service.
Impact
An attacker can hang the server process, denying service to legitimate users; no data confidentiality or integrity impact is described.
Attack surface
Reachable over the network via HTTP GET or POST requests to the web server; no authentication and no user interaction are required, and the requested resource does not need to exist.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but the reference is tagged Exploit and EPSS is 0.45 (98.7th percentile), indicating meaningful likelihood of exploitation.
What to do
- Upgrade GoAhead to a version later than v5.0.1, v4.1.1 or v3.6.5 that contains the fix; verify the vendor advisory for the corrected release.
- If immediate upgrade is not possible, restrict network access to the GoAhead listener with firewall rules or a reverse proxy that filters malformed multipart/form-data requests.
- Enforce request size and multipart parsing limits at the front-end proxy to reject oversized or malformed bodies before they reach GoAhead.
- Monitor the GoAhead process for CPU saturation and restart it automatically if it becomes unresponsive.
Detection
- Alert on sustained high CPU or unresponsive GoAhead processes correlated with inbound multipart/form-data requests.
- Log and inspect HTTP requests with multipart/form-data content types, especially those targeting non-existent resources or with malformed boundaries.
- Track repeated GET/POST requests from a single source that precede a service hang or restart.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2019-0889 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2019-0889 | ExploitThird Party Advisory |
Track CVE-2019-5097 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-5097), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.