Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: python313Packages.streaming-form-data

Found 1 matching suggestions

View:
Compact
Detailed
created 9 months ago Activity log
  • Created suggestion
Usage of unsafe random function in form-data for choosing boundary

Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js. This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.

Affected products

form-data
  • ==3.0.0 - 3.0.3
  • ==< 2.5.4
  • ==4.0.0 - 4.0.3

Matching in nixpkgs

Package maintainers