Description
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a malformed multipart request body can cause multipart Content-Type processing to take an extremely long time, resulting in uncontrolled resource consumption. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Published: 2026-10-06
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service (DoS) via ReDoS
Action: Patch
AI Analysis

Impact

A malformed multipart request body can trigger an extreme processing delay in the Content-Type validation phase, causing the system to consume excessive CPU resources and potentially become unresponsive. The flaw is rooted in a regular expression or parsing routine that is vulnerable to ReDoS, a condition classified as CWE‑1333. The primary impact is a denial of service; the vulnerability does not provide remote code execution or other higher impact capabilities.

Affected Systems

PayloadCMS (Payload) is affected in all releases from 3.0.0 up to, but not including, 3.90.0, as well as in canary releases before 4.0.0‑canary.34. Updating to 3.90.0 or any version 4.0.0‑canary.34 or later is required to eliminate the flaw.

Risk and Exploitability

With a CVSS score of 8.7, this is a high‑severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, so the precise exploitation probability is unknown. The attack vector is likely remote and public; a malicious client can craft a specially structured multipart request and send it over HTTP to trigger the DoS. No authentication or privileged access is needed, making the vulnerability readily exploitable from the internet.

Generated by OpenCVE AI on October 6, 2026 at 17:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Payload to version 3.90.0 or newer (including 4.0.0‑canary.34 and later).
  • If an immediate update is impossible, configure the server or reverse proxy to enforce strict limits on multipart request size and parsing time to mitigate resource exhaustion.
  • Continuously monitor request logs and performance metrics for unusually long multipart processing times to detect potential exploitation attempts.

Generated by OpenCVE AI on October 6, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2g7p-5934-q4w7 Payload: ReDoS in Multipart Content-Type Validation
History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a malformed multipart request body can cause multipart Content-Type processing to take an extremely long time, resulting in uncontrolled resource consumption. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Title Payload: ReDoS in Multipart Content-Type Validation
Weaknesses CWE-1333
CWE-400
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T17:30:01.567Z

Reserved: 2026-10-05T23:06:29.748Z

Link: CVE-2026-105854

cve-icon Vulnrichment

Updated: 2026-10-06T17:29:56.831Z

cve-icon NVD

Status : Received

Published: 2026-10-06T17:17:21.290

Modified: 2026-10-06T18:16:48.730

Link: CVE-2026-105854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:00:05Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity

  • CWE-400

    Uncontrolled Resource Consumption