Impact
A malformed multipart request body can trigger an extreme processing delay in the Content-Type validation phase, causing the system to consume excessive CPU resources and potentially become unresponsive. The flaw is rooted in a regular expression or parsing routine that is vulnerable to ReDoS, a condition classified as CWE‑1333. The primary impact is a denial of service; the vulnerability does not provide remote code execution or other higher impact capabilities.
Affected Systems
PayloadCMS (Payload) is affected in all releases from 3.0.0 up to, but not including, 3.90.0, as well as in canary releases before 4.0.0‑canary.34. Updating to 3.90.0 or any version 4.0.0‑canary.34 or later is required to eliminate the flaw.
Risk and Exploitability
With a CVSS score of 8.7, this is a high‑severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, so the precise exploitation probability is unknown. The attack vector is likely remote and public; a malicious client can craft a specially structured multipart request and send it over HTTP to trigger the DoS. No authentication or privileged access is needed, making the vulnerability readily exploitable from the internet.
OpenCVE Enrichment
Github GHSA