PatchSiren

form-data CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH form-data CVE published 2026-06-12

CVE-2026-12143

CVE-2026-12143 is a high-severity vulnerability in the form-data library, which could allow attackers to inject additional headers or smuggle multipart parts into requests. This vulnerability, classified as CWE-93 (CRLF injection), affects applications that use untrusted input as field names or filenames. The vulnerability was published on 2026-06-12T19:16:26.560Z and last modified on 2026-09-09T13:18:33.133Z.