CVE-2026-94440: 
cAdvisor vulnerability analysis and mitigation

Overview

CVE-2026-94440 is a memory limit bypass vulnerability in Go's standard library multipart form parser affecting the mime/multipart and net/textproto packages. When parsing a multipart form, the parser can bypass configured memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes. Affected Go versions include all releases before 1.26.9 and 1.27.0-0 through 1.27.1. The vulnerability was published on October 8, 2026, with patches released the same day. A CVSS base score has not yet been formally assigned, though it is estimated as Medium severity (GitHub Advisory, Feedly).

Technical details

The root cause is an allocation of resources without limits or throttling (CWE-770) in Go's multipart form parsing logic. When the remaining memory limit tracker falls below 400 bytes at the start of a new multipart part, a boundary condition in the line-reading logic fails to enforce the cap, allowing an unbounded read into memory. This is exploitable remotely by sending a crafted multipart HTTP request with a strategically sized payload that triggers the edge case. The issue is tracked upstream as Go issue #81741 and addressed in code change CL 847307 (GitHub Advisory, Go Issue).

Impact

Successful exploitation allows an unauthenticated remote attacker to exhaust server memory by sending crafted multipart form data, resulting in denial of service — the application may crash or become unresponsive. Any Go application that processes multipart form uploads using the standard library mime/multipart or net/textproto packages is potentially affected. There is no evidence of confidentiality or integrity impact; the primary risk is availability loss (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting very low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires no authentication and is network-accessible, lowering the barrier for exploitation if a PoC were to emerge (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Go-based web applications that accept multipart form uploads (e.g., file upload endpoints), which internally use mime/multipart from the Go standard library on a vulnerable version (< 1.26.9 or 1.27.0–1.27.1).
  2. Craft malicious multipart request: Construct an HTTP POST request with a Content-Type: multipart/form-data header. Design the multipart body so that the cumulative size of preceding parts consumes the memory limit down to just under 400 bytes before the start of a new part.
  3. Trigger boundary condition: Begin a new multipart part at this point and include an arbitrarily long line (e.g., a header line with no newline or an extremely long value) that the parser will read entirely into memory without enforcing the remaining limit.
  4. Exhaust server memory: Repeat or scale the request (e.g., via concurrent connections) to exhaust available server memory, causing the application process to crash or become unresponsive, achieving denial of service (GitHub Advisory, Go Issue).

Indicators of compromise

  • Network: Unusual volume of HTTP POST requests to file upload or form submission endpoints; multipart request bodies with abnormally large individual part headers or lines.
  • Logs: Application logs showing out-of-memory (OOM) errors or panics originating from mime/multipart or net/textproto stack frames; web server access logs with repeated large multipart POST requests from the same source IP.
  • Process: Go application process terminated unexpectedly with OOM kill signals (e.g., Linux kernel OOM killer logs referencing the Go process); sudden spikes in memory consumption correlated with multipart form processing.

Mitigation and workarounds

Update the Go toolchain to version 1.26.9 or later (for Go 1.26.x users) or 1.27.2 or later (for Go 1.27.x users), which include the fix for this vulnerability. All applications built with affected Go versions that handle multipart form data should be recompiled and redeployed using the patched toolchain. As a temporary workaround, operators can implement application-level request size limits (e.g., using http.MaxBytesReader) and rate limiting on multipart upload endpoints to reduce exposure until patching is complete (GitHub Advisory, Go Announce).

Community reactions

The vulnerability was announced via the official golang-announce mailing list alongside the Go 1.26.9 and 1.27.2 releases. Community discussion noted that this is one of ten CVEs addressed in those releases. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation (Go Announce).

Additional resources


Source: This report was generated using AI

Related cAdvisor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-97031HIGH7.5
  • cAdvisor logocAdvisor
  • prometheus-statsd-exporter-fips-0.22
NoYesOct 08, 2026
CVE-2026-94440HIGH7.5
  • cAdvisor logocAdvisor
  • crossplane-provider-aws-elasticache-fips
NoYesOct 08, 2026
CVE-2026-94448MEDIUM6.1
  • cAdvisor logocAdvisor
  • longhorn-share-manager-fips-1.9
NoYesOct 08, 2026
CVE-2026-97032MEDIUM5.9
  • cAdvisor logocAdvisor
  • task
NoYesOct 08, 2026
CVE-2026-97030NONEN/A
  • cAdvisor logocAdvisor
  • cluster-api-1.14
NoYesOct 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management