Vulnerability DatabaseCVE-2026-105854

CVE-2026-105854: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-105854 is a ReDoS (Regular Expression Denial of Service) vulnerability in the multipart Content-Type validation logic of Payload CMS, a free and open-source headless content management system. A malformed multipart request body can cause the Content-Type processing to take an extremely long time, resulting in uncontrolled resource consumption. Affected versions include >= 3.0.0, < 3.90.0 and canary versions >= 4.0.0-canary.0, < 4.0.0-canary.34. The vulnerability was published to the GitHub Advisory Database on October 6, 2026, with a CVSS v4 base score of 8.7 (High) (Github Advisory).

Technical details

The root cause is classified under CWE-400 (Uncontrolled Resource Consumption) and CWE-1333 (Inefficient Regular Expression Complexity), indicating that the multipart Content-Type parser uses a regular expression with potentially exponential worst-case complexity (Github Advisory). An unauthenticated remote attacker can send a specially crafted multipart HTTP request with a malformed Content-Type header, triggering catastrophic backtracking in the regex engine and causing the server process to consume excessive CPU cycles. No privileges or user interaction are required, and the attack can be automated at scale. The fix introduced in commit 0084bd5 bounds multipart request processing by adding a requestSizeLimit (defaulting to 50 MiB), stricter per-field/file/part limits, and improved cleanup logic to prevent resource exhaustion (Payload Commit).

Impact

Successful exploitation causes high availability impact on the vulnerable Payload CMS instance, as the server's CPU is consumed processing the malformed regex, potentially rendering the application unresponsive or causing a denial of service. There is no confidentiality or integrity impact — attackers cannot read data or modify content through this vulnerability. Because the attack is network-accessible, unauthenticated, and automatable, repeated requests could sustain a denial-of-service condition against any Payload CMS deployment that accepts multipart uploads (Github Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the advisory publication date. The NVD SSVC assessment classifies exploitation as "none" at time of analysis, though the vulnerability is marked as "Automatable: yes" due to the lack of authentication or user interaction requirements (Github Advisory). The EPSS score is 0.0, indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Payload CMS instances running versions >= 3.0.0 and < 3.90.0 (or canary versions < 4.0.0-canary.34) using tools like Shodan, Censys, or by inspecting HTTP response headers and JavaScript bundles for Payload version indicators.
  2. Identify multipart upload endpoint: Locate any endpoint that accepts multipart form data (e.g., file upload endpoints in Payload collections with upload enabled, typically at /api/<collection-slug>).
  3. Craft malformed Content-Type header: Construct an HTTP POST request with a Content-Type: multipart/form-data header containing a specially crafted, malformed boundary or parameter value designed to trigger catastrophic backtracking in the regex used to parse the Content-Type.
  4. Send the request: Transmit the crafted request to the target endpoint. No authentication is required. The server's regex engine will enter exponential backtracking, consuming CPU resources for an extended period.
  5. Repeat for sustained DoS: Automate sending multiple such requests concurrently to sustain CPU exhaustion and render the Payload CMS instance unavailable to legitimate users (Github Advisory).

Indicators of compromise

  • Network: Unusual volume of HTTP POST requests to Payload CMS upload endpoints (e.g., /api/<collection>/) with malformed or abnormally long Content-Type headers; requests that do not complete within expected timeframes.
  • Process: Sustained high CPU utilization by the Node.js process hosting Payload CMS without a corresponding increase in legitimate traffic; worker threads or event loop blocking observable via APM tools.
  • Logs: Application logs showing multipart parsing operations that take unusually long to complete or time out; repeated 503/504 errors or gateway timeouts from a reverse proxy in front of Payload CMS.
  • File System: Accumulation of incomplete temporary files in the configured tempFileDir (default: tmp/) if the server is partially processing malformed requests before timing out.

Mitigation and workarounds

Users should upgrade Payload CMS to version 3.90.0 or 4.0.0-canary.34 or later, which bound multipart request processing with a default requestSizeLimit of 50 MiB and enforce stricter per-file, per-field, and per-part limits (Github Advisory, Payload Release). If your application requires uploads larger than 50 MiB, explicitly configure the requestSizeLimit in your Payload config (e.g., requestSizeLimit: 75 * 1024 * 1024). As a temporary workaround prior to upgrading, consider placing a reverse proxy (e.g., nginx) in front of Payload that enforces request body size limits and rejects malformed Content-Type headers. After upgrading, regenerate Payload types (pnpm payload generate:types) and run any required database migrations.

Community reactions

The v3.90.0 release notes from the Payload CMS maintainers describe this as part of a set of "critical security fixes" and recommend upgrading as soon as possible, while intentionally omitting exploit details and attack surface descriptions from the release notes (Payload Release). The advisory was reported by researcher hwpark6804-gif and published by maintainer DanRibbens (Github Advisory). No significant broader media coverage or notable social media commentary has been identified beyond standard vulnerability aggregator coverage.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-106448HIGH8.9
  • JavaScript logoJavaScript
  • @stablelib/cbor
NoYesOct 06, 2026
CVE-2026-106447HIGH8.7
  • JavaScript logoJavaScript
  • @stablelib/cbor
NoYesOct 06, 2026
CVE-2026-105854HIGH8.7
  • JavaScript logoJavaScript
  • payload
NoYesOct 06, 2026
CVE-2026-105855HIGH7.6
  • JavaScript logoJavaScript
  • payload
NoYesOct 06, 2026
CVE-2026-105853HIGH7.1
  • JavaScript logoJavaScript
  • payload
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management