@strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling
- Severity:
- Medium
Description
A Denial-of-Service was found in the media upload process causing the server to crash without restarting, affecting either development and production environments.
Recommendation
Update the @strapi/plugin-upload package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.22.0
- Patched version(s): 4.22.0
References
Related Issues
- Handling untrusted input can result in a crash, leading to loss of availability / denial of service - CVE-2024-30253
- Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation - CVE-2026-33939
- Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects - CVE-2026-34043
- OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header - CVE-2026-59892
You might also like:
- Tags:
- npm
- @strapi/plugin-upload
Anything's wrong? Let us know Last updated on June 12, 2024


