← Vulnerability feed

Vulnerability record · CVE-2026-8162 · published 12 May 2026

CVE-2026-8162: Pillarjs multiparty vulnerability

PPillarjs · Multiparty

[email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose filename* parameter contains a malformed percent-encoding, the parser invokes decodeURI on the value without try/catch. The resulting URIError propagates as an uncaught exception and crashes the process. Impact: any service accepting multipart uploads via multiparty is affected. Workarounds: none. Upgrade to [email protected] or higher.

7.5 CVSS 3.1 High EPSS 0.58% · top 54.7% CWE-755 · CWE-755
7.5CVSS 3.1 base score
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

[email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose filename* parameter contains a malformed percent-encoding, the parser invokes decodeURI on the value without try/catch. The resulting URIError propagates as an uncaught exception and crashes the process. Impact: any service accepting multipart uploads via multiparty is affected. Workarounds: none. Upgrade to [email protected] or higher.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-8162 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-8159Pillarjs multiparty inefficient regular expression (redos) vulnerability[email protected] and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename param…EPSS 0.62%7.5CVE-2026-8161Pillarjs multiparty prototype pollution vulnerability[email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field…EPSS 0.53%7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed8.6CVE-2018-0155Cisco Catalyst BFD offload incomplete header handling denial of serviceCisco Catalyst 4500 and 4500-X series switches mishandle incomplete BFD headers in the BFD offload implementation, causing the iosd process to crash.…KEVEPSS 7.7%analysed8.8CVE-2021-38003Google Chrome V8 heap corruption via crafted HTML pageGoogle Chrome before 95.0.4638.69 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. A remote att…KEVEPSS 39%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2026-8162), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.