Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2g7p-5934-q4w7 | Payload: ReDoS in Multipart Content-Type Validation |
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and canary versions before 4.0.0-canary.34, a malformed multipart request body can cause multipart Content-Type processing to take an extremely long time, resulting in uncontrolled resource consumption. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34. | |
| Title | Payload: ReDoS in Multipart Content-Type Validation | |
| Weaknesses | CWE-1333 CWE-400 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T17:30:01.567Z
Reserved: 2026-10-05T23:06:29.748Z
Link: CVE-2026-105854
Updated: 2026-10-06T17:29:56.831Z
Status : Received
Published: 2026-10-06T17:17:21.290
Modified: 2026-10-06T18:16:48.730
Link: CVE-2026-105854
No data.
OpenCVE Enrichment
Updated: 2026-10-06T18:00:05Z
Github GHSA