Impact
Plug.Parsers.MULTIPART does not enforce its :length budget against all consumed resources, allowing an unauthenticated remote attacker to cause denial of service. The parser charges the :length limit only for part body bytes; part header bytes are never counted, and a part with an empty body costs zero. Every part whose Content-Disposition carries a non‑empty filename creates a fresh temporary file via Plug.Upload and retains a Plug.Upload struct for the duration of the request. An attacker can send a single request comprising many empty‑body file parts, keeping the overall payload well under the configured :length limit (8,000,000 bytes by default) while creating one temporary file per part, leading to inode and disk exhaustion and unbounded memory growth. This flaw is a moderate severity denial of service impact identified as CWE‑770.
Affected Systems
The vulnerability affects the elixir-plug Plug library from version 1.4.0 up to 1.20.2. Specifically, versions 1.4.0‑1.16.5, 1.17.0‑1.17.3, 1.18.0‑1.18.4, 1.19.1‑1.19.4, and 1.20.0‑1.20.2 are vulnerable. Any Elixir application that uses Plug.Parsers with the :multipart parser at its default configuration is impacted, regardless of authentication.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk, and the EPSS score of 1% indicates a low exploitation probability, while the lack of KEV listing suggests the exploit is not widely reported. However, the attack requires only HTTP reachability to a multipart endpoint with no authentication, making it an attractive target for attackers seeking to exhaust resources in their environment.
OpenCVE Enrichment