CVE-2025-7783
Severity CVSS v4.0:
CRITICAL
Type:
CWE-330
Use of Insufficiently Random Value
Publication date:
18/07/2025
Last modified:
03/11/2025
Description
Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.<br />
<br />
This issue affects form-data:
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL
References to Advisories, Solutions, and Tools
- https://github.com/form-data/form-data/commit/3d1723080e6577a66f17f163ecd345a21d8d0fd0
- https://github.com/form-data/form-data/security/advisories/GHSA-fjxv-7rqg-78g4
- https://lists.debian.org/debian-lts-announce/2025/07/msg00023.html
- https://github.com/form-data/form-data/security/advisories/GHSA-fjxv-7rqg-78g4



