Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.DIST
  • Bug#1109551: node-form-data: CVE-2025-7783

    From Salvatore Bonaccorso@21:1/5 to All on Sat Jul 19 23:00:01 2025
    Source: node-form-data
    Version: 4.0.1-1
    Severity: important
    Tags: security upstream
    X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

    Hi,

    The following vulnerability was published for node-form-data.

    CVE-2025-7783[0]:
    | Use of Insufficiently Random Values vulnerability in form-data
    | allows HTTP Parameter Pollution (HPP). This vulnerability is
    | associated with program files lib/form_data.Js. This issue affects
    | form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-7783
    https://www.cve.org/CVERecord?id=CVE-2025-7783
    [1] https://github.com/form-data/form-data/security/advisories/GHSA-fjxv-7rqg-78g4
    [2] https://github.com/form-data/form-data/commit/3d1723080e6577a66f17f163ecd345a21d8d0fd0

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Pragyansh Chaturvedi@21:1/5 to All on Sun Jul 27 19:50:01 2025
    Hi

    upstream has the fix: https://github.com/form-data/form-data/commit/3d1723080e6577a66f17f163ecd345a21d8d0fd0
    while debian has the fix: https://salsa.debian.org/js-team/node-form-data/-/commit/cee782f6ff789f389e6ce2f34ae9549d291e85be

    These fixes are different. The CVE fix in debian does not have a 50
    character boundary anymore, but a 62 character boundary now.
    This causes autopkgtest failure in node-superagent: https://ci.debian.net/packages/n/node-superagent/testing/amd64/62420387/,
    the payload size asserts now fail. This does not allow node-form-data to migrate.
    Please use the upstream's fix for this CVE instead of
    crypto.randomUUID() to preserve boundary length and not break other
    packages.

    Regards

    Pragyansh

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Pragyansh Chaturvedi@21:1/5 to All on Sun Jul 27 20:00:01 2025
    Hi

    upstream has the fix: https://github.com/form-data/form-data/commit/3d1723080e6577a66f17f163ecd345a21d8d0fd0
    while debian has the fix: https://salsa.debian.org/js-team/node-form-data/-/commit/cee782f6ff789f389e6ce2f34ae9549d291e85be

    These fixes are different. The CVE fix in debian does not have a 50
    character boundary anymore, but a 62 character boundary now.
    This causes autopkgtest failure in node-superagent: https://ci.debian.net/packages/n/node-superagent/testing/amd64/62420387/,
    the payload size asserts now fail. This does not allow node-form-data to migrate.
    Please use the upstream's fix for this CVE instead of
    crypto.randomUUID() to preserve boundary length and not break other
    packages.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Bob Worm
      Tue Jun 9 14:47:58 2026
      from Wales, Uk via Telnet
    • Krenn
      Tue Jun 9 11:18:15 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Tue Jun 9 10:31:07 2026
      from Wales, Uk via Telnet
    • Centurion
      Mon Jun 8 23:30:43 2026
      from Berea, Ohio via Telnet
    • Centurion
      Mon Jun 8 21:33:11 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 47:39:34
    Calls: 12,112
    Calls today: 3
    Files: 15,010
    Messages: 6,518,503

© >>> Magnum BBS <<<, 2026