Red Hat Security Advisory: Ansible plug-ins for Red Hat Developer Hub Product Release Update
A denial of service (DoS) vulnerability exists in Multer, a Node.js middleware used in Red Hat Ansible Automation Platform 2.1, caused by processing deeply nested multipart form data fields. An attacker can send a crafted HTTP request with deeply nested field names, causing excessive CPU and memory consumption, leading to service unavailability. Red Hat has not released a patch yet but recommends configuring the 'limits.fields' option in Multer to limit the number of processed fields as a partial mitigation.
AI Analysis
Technical Summary
CVE-2026-5079 is a denial of service vulnerability in Multer, a Node.js middleware for handling multipart/form-data, used in Red Hat Ansible Automation Platform 2.1. The flaw allows a remote attacker to send a single HTTP request with deeply nested multipart form data field names, forcing the allocation of deeply nested object structures that consume excessive CPU and memory resources. This resource exhaustion leads to denial of service on affected systems. The vulnerability is relevant for Red Hat products exposing Multer-based services to untrusted network input. Red Hat classifies this as an important security issue with a CVSS v3 base score of 7.5 (high severity).
Potential Impact
Successful exploitation results in denial of service due to resource exhaustion (CPU and memory) on affected systems running Multer middleware. This causes service unavailability but does not impact confidentiality or integrity. The vulnerability affects Red Hat Ansible Automation Platform 2.1 components that use Multer for multipart form data processing.
Mitigation Recommendations
No official patch or fix is currently available from Red Hat. As a partial mitigation, administrators should configure the 'limits.fields' option in the Multer middleware to restrict the maximum number of fields processed from multipart form data, thereby limiting resource consumption. This mitigation requires an application restart to take effect and does not fully prevent the vulnerability. Monitor Red Hat advisories for future patches or updates.
Red Hat Security Advisory: Ansible plug-ins for Red Hat Developer Hub Product Release Update
Description
A denial of service (DoS) vulnerability exists in Multer, a Node.js middleware used in Red Hat Ansible Automation Platform 2.1, caused by processing deeply nested multipart form data fields. An attacker can send a crafted HTTP request with deeply nested field names, causing excessive CPU and memory consumption, leading to service unavailability. Red Hat has not released a patch yet but recommends configuring the 'limits.fields' option in Multer to limit the number of processed fields as a partial mitigation.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-5079 is a denial of service vulnerability in Multer, a Node.js middleware for handling multipart/form-data, used in Red Hat Ansible Automation Platform 2.1. The flaw allows a remote attacker to send a single HTTP request with deeply nested multipart form data field names, forcing the allocation of deeply nested object structures that consume excessive CPU and memory resources. This resource exhaustion leads to denial of service on affected systems. The vulnerability is relevant for Red Hat products exposing Multer-based services to untrusted network input. Red Hat classifies this as an important security issue with a CVSS v3 base score of 7.5 (high severity).
Potential Impact
Successful exploitation results in denial of service due to resource exhaustion (CPU and memory) on affected systems running Multer middleware. This causes service unavailability but does not impact confidentiality or integrity. The vulnerability affects Red Hat Ansible Automation Platform 2.1 components that use Multer for multipart form data processing.
Mitigation Recommendations
No official patch or fix is currently available from Red Hat. As a partial mitigation, administrators should configure the 'limits.fields' option in the Multer middleware to restrict the maximum number of fields processed from multipart form data, thereby limiting resource consumption. This mitigation requires an application restart to take effect and does not fully prevent the vulnerability. Monitor Red Hat advisories for future patches or updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:65118
- Cve Count
- 16
- Additional Cves
- ["CVE-2026-67213","CVE-2026-67214","CVE-2026-67313","CVE-2026-67314","CVE-2026-67320","CVE-2026-67321","CVE-2026-73563","CVE-2026-73566","CVE-2026-75838","CVE-2026-75899","CVE-2026-75931","CVE-2026-75975","CVE-2026-76172","CVE-2026-84292","CVE-2026-84394"]
- Cvss Version
- null
Threat ID: 6aa15f68acd9273b49617fb4
Added to database: 09/09/2026, 13:30:16 UTC
Last enriched: 09/09/2026, 13:51:08 UTC
Last updated: 09/09/2026, 22:52:13 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.