Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-56814— Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)

Quick assessment

Affected
elixir-plug plug
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

elixir-plug plug是elixir-plug团队的一个Web应用程序组件框架。 elixir-plug plug存在资源管理错误漏洞,该漏洞源于Plug.Parsers.MULTIPART解析器未对资源消耗强制执行:length预算,可能导致未经身份验证的远程攻击者通过发送大量空文件部分请求造成拒绝服务。以下版本受到影响:1.4.0至1.16.6之前版本、1.17.0至1.17.4之前版本、1.18.0至1.18.5之前版本、1.19.0至1.19.5之前版本和1.20.0至1.20.3之前版

CVSS 6.9 · Medium EPSS 1.08% · P64

Affected Version Matrix 6

VendorProduct Version RangeStatus
elixir-plug plug 1.4.0-rc.0< 1.16.6 affected
1.17.0< 1.17.4 affected
1.18.0< 1.18.5 affected
1.19.1< 1.19.5 affected
1.20.0< 1.20.3 affected
c52b2f32c90bccd718202bafccb5f95594e30183< * affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56814

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)
Source: CVE Program / CVE List V5
Vulnerability Description
Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce its :length budget against all consumed resources, allowing an unauthenticated remote attacker to cause denial of service. The parser charges the :length limit only for part body bytes; part header bytes are never counted, and a part with an empty body costs zero. Because every part whose Content-Disposition carries a non-empty filename creates a fresh temporary file (via Plug.Upload) and retains a Plug.Upload struct for the duration of the request, an attacker can send a single request composed of many empty-body file parts. Such a request stays well under the configured :length limit (8,000,000 bytes by default) while creating one temporary file per part, leading to inode and disk exhaustion and unbounded memory growth. Any application using Plug.Parsers with the :multipart parser is affected, and no authentication is required, only reachability of a multipart endpoint over HTTP. This vulnerability is associated with program files lib/plug/parsers/multipart.ex and program routines Plug.Parsers.MULTIPART.parse_multipart/2, Plug.Parsers.MULTIPART.parse_multipart_headers/5, Plug.Parsers.MULTIPART.parse_multipart_body/4, and Plug.Parsers.MULTIPART.parse_multipart_file/4. This issue affects plug: from 1.4.0-rc.0 before 1.16.6, from 1.17.0 before 1.17.4, from 1.18.0 before 1.18.5, from 1.19.1 before 1.19.5, and from 1.20.0 before 1.20.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5
Vulnerability Title
elixir-plug plug 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
elixir-plug plug是elixir-plug团队的一个Web应用程序组件框架。 elixir-plug plug存在资源管理错误漏洞,该漏洞源于Plug.Parsers.MULTIPART解析器未对资源消耗强制执行:length预算,可能导致未经身份验证的远程攻击者通过发送大量空文件部分请求造成拒绝服务。以下版本受到影响:1.4.0至1.16.6之前版本、1.17.0至1.17.4之前版本、1.18.0至1.18.5之前版本、1.19.0至1.19.5之前版本和1.20.0至1.20.3之前版
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
elixir-plug plug 1.4.0-rc.0 ~ 1.16.6 cpe:2.3:a:elixir-plug:plug:*:*:*:*:*:*:*:*
elixir-plug plug c52b2f32c90bccd718202bafccb5f95594e30183 ~ * cpe:2.3:a:elixir-plug:plug:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-56814

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56814

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-56814 (6)

Vendor Advisories for CVE-2026-56814 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-56814

No comments yet


Leave a comment