CVE-2025-7783

EUVD-2025-21906
Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.

This issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-form-data
bionic
Fixed 0.1.0-1ubuntu0.18.04.1~esm1
released
focal
Fixed 3.0.0-2ubuntu0.1~esm1
released
jammy
Fixed 3.0.1-1ubuntu0.1~esm1
released
noble
Fixed 4.0.0-1ubuntu0.1
released
plucky
ignored
questing
not-affected
trusty
Fixed 0.1.0-1ubuntu0.14.04.1~esm1
released
xenial
Fixed 0.1.0-1ubuntu0.16.04.1~esm1
released