
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-94440 is a memory limit bypass vulnerability in Go's standard library multipart form parser affecting the mime/multipart and net/textproto packages. When parsing a multipart form, the parser can bypass configured memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes. Affected Go versions include all releases before 1.26.9 and 1.27.0-0 through 1.27.1. The vulnerability was published on October 8, 2026, with patches released the same day. A CVSS base score has not yet been formally assigned, though it is estimated as Medium severity (GitHub Advisory, Feedly).
The root cause is an allocation of resources without limits or throttling (CWE-770) in Go's multipart form parsing logic. When the remaining memory limit tracker falls below 400 bytes at the start of a new multipart part, a boundary condition in the line-reading logic fails to enforce the cap, allowing an unbounded read into memory. This is exploitable remotely by sending a crafted multipart HTTP request with a strategically sized payload that triggers the edge case. The issue is tracked upstream as Go issue #81741 and addressed in code change CL 847307 (GitHub Advisory, Go Issue).
Successful exploitation allows an unauthenticated remote attacker to exhaust server memory by sending crafted multipart form data, resulting in denial of service — the application may crash or become unresponsive. Any Go application that processes multipart form uploads using the standard library mime/multipart or net/textproto packages is potentially affected. There is no evidence of confidentiality or integrity impact; the primary risk is availability loss (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting very low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires no authentication and is network-accessible, lowering the barrier for exploitation if a PoC were to emerge (GitHub Advisory).
mime/multipart from the Go standard library on a vulnerable version (< 1.26.9 or 1.27.0–1.27.1).Content-Type: multipart/form-data header. Design the multipart body so that the cumulative size of preceding parts consumes the memory limit down to just under 400 bytes before the start of a new part.mime/multipart or net/textproto stack frames; web server access logs with repeated large multipart POST requests from the same source IP.Update the Go toolchain to version 1.26.9 or later (for Go 1.26.x users) or 1.27.2 or later (for Go 1.27.x users), which include the fix for this vulnerability. All applications built with affected Go versions that handle multipart form data should be recompiled and redeployed using the patched toolchain. As a temporary workaround, operators can implement application-level request size limits (e.g., using http.MaxBytesReader) and rate limiting on multipart upload endpoints to reduce exposure until patching is complete (GitHub Advisory, Go Announce).
The vulnerability was announced via the official golang-announce mailing list alongside the Go 1.26.9 and 1.27.2 releases. Community discussion noted that this is one of ten CVEs addressed in those releases. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation (Go Announce).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."