CVE-2020-7699: Express-Fileupload Project Express-Fileupload
Critical severity, CVSS 9.8. EPSS: 4.8% chance of exploitation in the next 30 days.
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
Affected products
- Express-Fileupload Project Express-Fileupload: before 1.1.8 (fixed in 1.1.8)
- Netapp Max Data: affected versions not specified
Published 2020-07-30. Last modified 2026-06-17.