Contents

Web & Networking › HTTP

multipart/form-data

The encoding used to upload files from forms.

Also known as: multipart form data, multipart, form-data

multipart/form-data is the encoding browsers use when a form includes files: the body is split into parts separated by a boundary string, each with its own headers (Content-Disposition, Content-Type), so text fields and binary files travel in one request.

Content-Type: multipart/form-data; boundary=----abc123
------abc123
Content-Disposition: form-data; name="title"
My photo
------abc123
Content-Disposition: form-data; name="file"; filename="p.jpg"
Content-Type: image/jpeg
[binary bytes]

Servers parse it with dedicated multipart parsers — never by hand — enforcing size limits per file and overall, since a “form post” can legitimately be gigabytes.

The classic mistakes:

  • Parsing it manually. Boundary handling, encodings and nested quirks are a CVE farm. Use the framework’s parser.
  • No size limits. Unlimited multipart parsing is a memory-exhaustion vector. Cap file size, total size and part count before parsing buffers.
  • Trusting filename and Content-Type. Both come from the client. Validate magic bytes and extension server-side; sanitise filenames (no paths) before storage.
  • Buffering huge uploads in the app. Holding multi-hundred-MB parts in memory kills workers. Stream to disk or object storage; better, use presigned URLs so bytes bypass the app.
  • Wrong encoding for the job. Plain field-only forms should use application/x-www-form-urlencoded; JSON APIs should send JSON. Multipart is for mixed file+field payloads.
  • Forgetting CSRF. Cookie-authed multipart endpoints are classic CSRF targets — the browser happily submits them. Protect accordingly.
  • Assuming order or single files. Parts arrive in order but clients vary; handle multiple files and missing fields defensively.

How to handle it: framework parser, strict size caps, stream large parts, validate content after receipt, and consider direct-to-storage uploads for anything big. It’s the web’s file envelope — convenient, attacker-shaped, and safe only with limits.