form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `"` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.

Project Subscriptions

Vendors Products
Form-data Subscribe
Form-data Subscribe
Service Mesh Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hmw2-7cc7-3qxx form-data: CRLF injection in form-data via unescaped multipart field names and filenames
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:33155 cve-icon
https://access.redhat.com/errata/RHSA-2026:33160 cve-icon
https://access.redhat.com/errata/RHSA-2026:33163 cve-icon
https://access.redhat.com/errata/RHSA-2026:33173 cve-icon
https://access.redhat.com/errata/RHSA-2026:33183 cve-icon
https://access.redhat.com/errata/RHSA-2026:34342 cve-icon
https://access.redhat.com/errata/RHSA-2026:36319 cve-icon
https://access.redhat.com/errata/RHSA-2026:36625 cve-icon
https://access.redhat.com/errata/RHSA-2026:36754 cve-icon
https://access.redhat.com/errata/RHSA-2026:40262 cve-icon
https://access.redhat.com/errata/RHSA-2026:41031 cve-icon
https://access.redhat.com/errata/RHSA-2026:41066 cve-icon
https://access.redhat.com/errata/RHSA-2026:41928 cve-icon
https://access.redhat.com/errata/RHSA-2026:41929 cve-icon
https://access.redhat.com/errata/RHSA-2026:41951 cve-icon
https://access.redhat.com/errata/RHSA-2026:42146 cve-icon
https://access.redhat.com/errata/RHSA-2026:42796 cve-icon
https://access.redhat.com/errata/RHSA-2026:43052 cve-icon
https://access.redhat.com/errata/RHSA-2026:44263 cve-icon
https://access.redhat.com/errata/RHSA-2026:44267 cve-icon
https://access.redhat.com/errata/RHSA-2026:48124 cve-icon
https://access.redhat.com/errata/RHSA-2026:48151 cve-icon
https://access.redhat.com/errata/RHSA-2026:48693 cve-icon
https://access.redhat.com/errata/RHSA-2026:50300 cve-icon
https://access.redhat.com/security/cve/CVE-2026-12143 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2488480 cve-icon
https://cwe.mitre.org/data/definitions/93.html cve-icon cve-icon cve-icon
https://github.com/form-data/form-data/commit/64190db548c0179e37206858e39f27cf513e9435 cve-icon cve-icon cve-icon
https://github.com/form-data/form-data/commit/be3f3cf553978bac15a5182f1f3c3d2d38ccf229 cve-icon cve-icon cve-icon
https://github.com/form-data/form-data/commit/c7133499c2ee1b80c678e411244f4442bf902045 cve-icon cve-icon cve-icon
https://github.com/form-data/form-data/security/advisories/GHSA-hmw2-7cc7-3qxx cve-icon cve-icon cve-icon cve-icon
https://html.spec.whatwg.org/multipage/form-control-infrastructure.html#multipart-form-data cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-12143 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12143.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-12143 cve-icon
https://www.npmjs.com/package/form-data cve-icon cve-icon cve-icon
History

Tue, 30 Jun 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat service Mesh
CPEs cpe:/a:redhat:service_mesh:2.6::el8
cpe:/a:redhat:service_mesh:3.0::el9
cpe:/a:redhat:service_mesh:3.1::el9
cpe:/a:redhat:service_mesh:3.2::el9
cpe:/a:redhat:service_mesh:3.3::el9
Vendors & Products Redhat
Redhat service Mesh
References
Metrics threat_severity

None

threat_severity

Important


Fri, 12 Jun 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Form-data
Form-data form-data
Vendors & Products Form-data
Form-data form-data

Fri, 12 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Description form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `"` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.
Title form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: harborist

Published:

Updated: 2026-08-12T12:04:57.173Z

Reserved: 2026-06-12T17:33:29.185Z

Link: CVE-2026-12143

cve-icon Vulnrichment

Updated: 2026-08-12T12:04:57.173Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-12T19:16:26.560

Modified: 2026-08-12T12:17:45.160

Link: CVE-2026-12143

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-12T18:01:30Z

Links: CVE-2026-12143 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T19:30:31Z

Weaknesses