CVE-2025-24033 – Fastify/multipart Temporary File Lease

CVE ID : CVE-2025-24033

Published : Jan. 23, 2025, 6:15 p.m. | 26 minutes ago

Description : @fastify/multipart is a Fastify plugin for parsing the multipart content-type. Prior to versions 8.3.1 and 9.0.3, the `saveRequestFiles` function does not delete the uploaded temporary files when user cancels the request. The issue is fixed in versions 8.3.1 and 9.0.3. As a workaround, do not use `saveRequestFiles`.

Severity: 7.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Go to Source