CVE-2025-24033

@fastify/multipart is a Fastify plugin for parsing the multipart content-type. Prior to versions 8.3.1 and 9.0.3, the `saveRequestFiles` function does not delete the uploaded temporary files when user cancels the request. The issue is fixed in versions 8.3.1 and 9.0.3. As a workaround, do not use `saveRequestFiles`.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) @fastify/multipart es un complemento de Fastify para analizar el tipo de contenido multipart. Antes de las versiones 8.3.1 y 9.0.3, la función `saveRequestFiles` no elimina los archivos temporales cargados cuando el usuario cancela la solicitud. El problema se solucionó en las versiones 8.3.1 y 9.0.3. Como workaround, no use `saveRequestFiles`.

23 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 18:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-24033

Mitre link : CVE-2025-24033

CVE.ORG link : CVE-2025-24033


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling