CVE-2026-12143: Form-Data

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `"` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.

Affected products

  • Form-Data Form-Data: before 2.5.6 (fixed in 2.5.6); from 3.0.0, before 3.0.5 (fixed in 3.0.5); from 4.0.0, before 4.0.6 (fixed in 4.0.6)
  • Red Hat Cluster Observability Operator 1.5.0: before 1782840519 (fixed in 1782840519); before 1782839981 (fixed in 1782839981); before 1782839193 (fixed in 1782839193); before 1782838753 (fixed in 1782838753); before 1782839279 (fixed in 1782839279); before 1782840539 (fixed in 1782840539); …
  • Red Hat Cryostat 4
  • Red Hat Cryostat 4 On Rhel 9: before 4.2.0-13 (fixed in 4.2.0-13)
  • Red Hat Migration Toolkit For Applications 8
  • Red Hat Multicluster Engine For Kubernetes 2.1: before 1787079364 (fixed in 1787079364)
  • Red Hat Multicluster Engine For Kubernetes 2.11: before 1787065052 (fixed in 1787065052)
  • Red Hat Multicluster Engine For Kubernetes 2.6: before 1787264250 (fixed in 1787264250)
  • Red Hat Multicluster Engine For Kubernetes 2.8: before 1787259048 (fixed in 1787259048)
  • Red Hat Multicluster Engine For Kubernetes 2.9: before 1787079359 (fixed in 1787079359)
  • Red Hat Network Observability Operator
  • Red Hat Node Healthcheck Operator
  • Red Hat Openshift Pipelines
  • Red Hat Openshift Service Mesh 3
  • Red Hat Red Hat 3scale API Management Platform 2
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787687062 (fixed in 1787687062)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787339249 (fixed in 1787339249)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1787339248 (fixed in 1787339248)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787341780 (fixed in 1787341780)
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787339213 (fixed in 1787339213)
  • Red Hat Red Hat Advanced Cluster Security 4.9: before 1783357116 (fixed in 1783357116)
  • Red Hat Red Hat Advanced Cluster Security For Kubernetes 4.10: before 1783357140 (fixed in 1783357140)
  • Red Hat Red Hat Amq Broker 7.13.6
  • Red Hat Red Hat Amq Broker 7.14.1
  • Red Hat Red Hat Ansible Automation Platform 2
  • and 55 more

Published 2026-06-12. Last modified 2026-09-11.