CVE-2026-105854: CVE-2026-105854: Regular Expression Denial of Service (ReDoS) and Uncontrolled Resource Consumption in Payload CMS
CVE-2026-105854: Regular Expression Denial of Service (ReDoS) and Uncontrolled Resource Consumption in Payload CMS Vulnerability ID: CVE-2026-105854 CVSS Score: 8.7 Published: 2026-10-06 Payload CMS, a popular open-
CVE-2026-105854: Regular Expression Denial of Service (ReDoS) and Uncontrolled Resource Consumption in Payload CMS
Vulnerability ID: CVE-2026-105854
CVSS Score: 8.7
Published: 2026-10-06
Payload CMS, a popular open-source headless Content Management System, contains a critical Regular Expression Denial of Service (ReDoS) and uncontrolled resource consumption vulnerability in versions prior to 3.90.0 and canary versions prior to 4.0.0-canary.34. Due to nested quantifiers in the multipart boundary regex validation pattern, and the absence of streaming backpressure controls, remote attackers can trigger catastrophic backtracking and memory exhaustion. This blocks the single-threaded Node.js event loop, resulting in a persistent and complete Denial of Service (DoS).
TL;DR
Unauthenticated remote attackers can freeze the Payload CMS Node.js event loop and exhaust heap memory by sending malformed multipart HTTP requests, exploiting a ReDoS flaw in the boundary regex parser and a lack of request size limits in stream processing.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-1333, CWE-400
- Attack Vector: Network
- CVSS Score: 8.7 (High)
- Exploit Status: poc
- KEV Status: not-listed
- Remediation Status: patched
Affected Systems
- Payload CMS open-source application server
-
payload: >= 3.0.0, < 3.90.0 (Fixed in:
3.90.0) -
payload: >= 4.0.0-canary.0, < 4.0.0-canary.34 (Fixed in:
4.0.0-canary.34)
Code Analysis
Commit: 0084bd5
fix: prevent DoS/ReDoS vulnerabilities by implementing streaming parser limits and safe cancellation
Mitigation Strategies
- Upgrade the Payload CMS dependencies to version 3.90.0 or higher.
- Enforce maximum length limitations on the HTTP Content-Type header at the edge firewall or WAF layer.
- Configure active stream timeouts on reverse proxies to interrupt hanging backend connections.
Remediation Steps:
- Identify all deployed nodes running vulnerable versions of Payload CMS.
- Update the project package.json to pin payload to '^3.90.0' or higher.
- Run your package manager install command (e.g., 'npm install' or 'pnpm install') to update the lockfile.
- Redeploy the application to production and monitor server CPU utilization for ReDoS anomalies.
References
- Payload CMS Security Advisory GHSA-2g7p-5934-q4w7
- Payload CMS GitHub Release v3.90.0
- CVE Official Record - CVE-2026-105854
Read the full report for CVE-2026-105854 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.