Description
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0736 | Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0. |
Github GHSA |
GHSA-7xfp-9c55-5vqj | Remote Memory Exposure in request |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-16T17:28:08.484Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2017-16026
No data.
Status : Modified
Published: 2018-06-04T19:29:01.537
Modified: 2024-11-21T03:15:41.300
Link: CVE-2017-16026
OpenCVE Enrichment
No data.
EUVD
Github GHSA