CVE-2017-16026: vulnerability in HackerOne request node module
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A vulnerability in the Request HTTP client library allows attackers to leak sensitive data from server memory when uploading files through multipart requests with specially crafted numeric body parameters. This could expose passwords, tokens, or other confidential information.
CWE-201 (Information Exposure Through an Error Message) manifests when multipart requests with numeric body types cause the Request library to include uninitialized memory in the HTTP body. The vulnerability affects versions 2.2.6 to 2.47.0 and 2.51.0 to 2.67.0, enabling memory disclosure attacks without requiring authentication or special privileges beyond the ability to trigger multipart uploads.