
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-105854 is a ReDoS (Regular Expression Denial of Service) vulnerability in the multipart Content-Type validation logic of Payload CMS, a free and open-source headless content management system. A malformed multipart request body can cause the Content-Type processing to take an extremely long time, resulting in uncontrolled resource consumption. Affected versions include >= 3.0.0, < 3.90.0 and canary versions >= 4.0.0-canary.0, < 4.0.0-canary.34. The vulnerability was published to the GitHub Advisory Database on October 6, 2026, with a CVSS v4 base score of 8.7 (High) (Github Advisory).
The root cause is classified under CWE-400 (Uncontrolled Resource Consumption) and CWE-1333 (Inefficient Regular Expression Complexity), indicating that the multipart Content-Type parser uses a regular expression with potentially exponential worst-case complexity (Github Advisory). An unauthenticated remote attacker can send a specially crafted multipart HTTP request with a malformed Content-Type header, triggering catastrophic backtracking in the regex engine and causing the server process to consume excessive CPU cycles. No privileges or user interaction are required, and the attack can be automated at scale. The fix introduced in commit 0084bd5 bounds multipart request processing by adding a requestSizeLimit (defaulting to 50 MiB), stricter per-field/file/part limits, and improved cleanup logic to prevent resource exhaustion (Payload Commit).
Successful exploitation causes high availability impact on the vulnerable Payload CMS instance, as the server's CPU is consumed processing the malformed regex, potentially rendering the application unresponsive or causing a denial of service. There is no confidentiality or integrity impact — attackers cannot read data or modify content through this vulnerability. Because the attack is network-accessible, unauthenticated, and automatable, repeated requests could sustain a denial-of-service condition against any Payload CMS deployment that accepts multipart uploads (Github Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the advisory publication date. The NVD SSVC assessment classifies exploitation as "none" at time of analysis, though the vulnerability is marked as "Automatable: yes" due to the lack of authentication or user interaction requirements (Github Advisory). The EPSS score is 0.0, indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified.
/api/<collection-slug>).Content-Type: multipart/form-data header containing a specially crafted, malformed boundary or parameter value designed to trigger catastrophic backtracking in the regex used to parse the Content-Type./api/<collection>/) with malformed or abnormally long Content-Type headers; requests that do not complete within expected timeframes.tempFileDir (default: tmp/) if the server is partially processing malformed requests before timing out.Users should upgrade Payload CMS to version 3.90.0 or 4.0.0-canary.34 or later, which bound multipart request processing with a default requestSizeLimit of 50 MiB and enforce stricter per-file, per-field, and per-part limits (Github Advisory, Payload Release). If your application requires uploads larger than 50 MiB, explicitly configure the requestSizeLimit in your Payload config (e.g., requestSizeLimit: 75 * 1024 * 1024). As a temporary workaround prior to upgrading, consider placing a reverse proxy (e.g., nginx) in front of Payload that enforces request body size limits and rejects malformed Content-Type headers. After upgrading, regenerate Payload types (pnpm payload generate:types) and run any required database migrations.
The v3.90.0 release notes from the Payload CMS maintainers describe this as part of a set of "critical security fixes" and recommend upgrading as soon as possible, while intentionally omitting exploit details and attack surface descriptions from the release notes (Payload Release). The advisory was reported by researcher hwpark6804-gif and published by maintainer DanRibbens (Github Advisory). No significant broader media coverage or notable social media commentary has been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."