← Back to CVE List

CVE-2017-1000098

Published: 2017-10-05T01:29Z
Last Modified: 2024-11-21T03:04Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt