CVE-2026-12143
form-data form-data, Cryostat 4 on RHEL 9, Red Hat Data Grid 8.6.2 취약점
form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional...
- 대응 우선순위
- 점검
- CVSS
- 8.7
- EPSS
- 0.53% 백분위 42.2% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.13