Impact
Parsing a multipart form in Go’s standard library can bypass the configured memory limit and allow an attacker to read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes. This flaw can lead to excessive memory consumption and potentially crash the application, resulting in a denial‑of‑service condition for the service or system using the library.
Affected Systems
The vulnerability affects the Go standard library packages net/textproto and mime/multipart, impacting all Go applications that rely on the default multipart parsing routines and that have not been updated to a version where the fix has been applied. No specific version range is listed, so any Go installation preceding the patch is potentially vulnerable.
Risk and Exploitability
Based on the description, the likely attack vector is an external attacker sending a multipart HTTP request with a very long header line; no authentication or privileged access is required. An exploit would cause the application to allocate memory beyond its intended limit. The CVSS score is undefined, but the potential to exhaust memory makes this a high‑impact vulnerability. Neither the EPSS score nor an entry in CISA’s KEV catalog is available, indicating no publicly known exploits at the time of this analysis.
OpenCVE Enrichment