CVE-2026-94440
Received Received - Intake

Memory Limit Bypass in Go HTTP Multipart Form Parsing

Vulnerability report for CVE-2026-94440, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Go Project

Description

Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
Go standard library net/textproto 0
Go standard library net/textproto 1.27.0-0
Go standard library mime/multipart 0
Go standard library mime/multipart 1.27.0-0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in parsing multipart form data in Go's standard library. When processing such forms, the system may bypass memory limits and read an excessively long line into memory if the remaining memory limit at the start of a part is less than 400 bytes.

Impact Analysis

This vulnerability could lead to denial-of-service conditions by consuming excessive memory, potentially crashing applications or servers. It may also expose sensitive data if memory is improperly accessed.

Compliance Impact

This vulnerability could potentially lead to denial-of-service conditions or unauthorized memory access, which may impact data integrity and availability. However, the provided CVE data does not specify direct compliance implications for standards like GDPR or HIPAA.

Mitigation Strategies

Update to a patched version of Go that fixes the multipart form parsing issue. Monitor Go releases for security updates and apply them promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94440. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart