Description
Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Parsing a multipart form in Go’s standard library can bypass the configured memory limit and allow an attacker to read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes. This flaw can lead to excessive memory consumption and potentially crash the application, resulting in a denial‑of‑service condition for the service or system using the library.

Affected Systems

The vulnerability affects the Go standard library packages net/textproto and mime/multipart, impacting all Go applications that rely on the default multipart parsing routines and that have not been updated to a version where the fix has been applied. No specific version range is listed, so any Go installation preceding the patch is potentially vulnerable.

Risk and Exploitability

Based on the description, the likely attack vector is an external attacker sending a multipart HTTP request with a very long header line; no authentication or privileged access is required. An exploit would cause the application to allocate memory beyond its intended limit. The CVSS score is undefined, but the potential to exhaust memory makes this a high‑impact vulnerability. Neither the EPSS score nor an entry in CISA’s KEV catalog is available, indicating no publicly known exploits at the time of this analysis.

Generated by OpenCVE AI on October 9, 2026 at 00:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Go runtime release that contains the patch for this memory limit bypass flaw.
  • Where possible, adjust application logic to enforce stricter limits on multipart form data, for example by configuring a minimum allowed part boundary or by parsing incoming data in smaller chunks.
  • Implement application‑level checks that reject HTTP requests with content lengths exceeding a safe threshold before invoking the Go standard library’s multipart parser.

Generated by OpenCVE AI on October 9, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-789

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.
Title Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:58.959Z

Reserved: 2026-09-21T16:43:04.757Z

Link: CVE-2026-94440

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:04.917

Modified: 2026-10-08T23:17:04.917

Link: CVE-2026-94440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T01:00:14Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value