multer
npm14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting multerpage 1 of 1
- CVE-2025-47935HIGHCVSS 7.5EG 7.5fixed in 2.0.02025-05-19
Multer is a node.js middleware for handling `multipart/form-data`. Versions prior to 2.0.0 are vulnerable to a resource exhaustion and memory leak issue due to improper stream handling. When the HTTP request stream emits an error, the inte…
- CVE-2025-47944HIGHCVSS 7.5EG 7.5fixed in 2.0.02025-05-19
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.0 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed mu…
- CVE-2025-48997HIGHCVSS 8.7EG 8.7fixed in 2.0.12025-06-03
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to trigger a Denial of Service (DoS) by sending an upload file…
- CVE-2025-7338HIGHCVSS 7.5EG 7.5fixed in 2.0.22025-07-17
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.2 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed mu…
- CVE-2026-2359HIGHCVSS 7.5EG 7.5fixed in 2.1.02026-02-27
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing reso…
- CVE-2026-3304HIGHCVSS 7.5EG 7.5fixed in 2.1.02026-02-27
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaust…
- CVE-2026-3520HIGHCVSS 7.5EG 7.5fixed in 2.1.12026-03-04
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. …
- CVE-2026-5038HIGHCVSS 7.5EG 7.5fixed in 2.2.0 or 3.0.0-alpha.2, by version range2026-06-15
Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() cal…
- CVE-2026-5079HIGHCVSS 7.5EG 7.5fixed in 2.2.0 or 3.0.0-alpha.2, by version range2026-06-15
Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on n…
- CVE-2026-77037HIGHCVSS 7.5EG 7.5fixed in 2.3.02026-08-28
vulnerable: 2.2.0
multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not cl…
- CVE-2026-77063LOWCVSS 3.7EG 3.7fixed in 2.3.02026-08-28
multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in multer's file stream handling can allow a file that exceeds the c…
- CVE-2026-77078HIGHCVSS 7.5EG 7.5fixed in 2.3.02026-08-28
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. Th…
- CVE-2026-82333HIGHCVSS 7.5EG 7.5fixed in 2.3.02026-08-28
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the even…
- CVE-2026-88932MEDIUMCVSS 5.3EG 5.3fixed in 2.4.02026-09-14
multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are…
Check whether multer is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for multer CVEs against the assets you own.
Book a Demo →