multer
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting multerpage 1 of 1
- CVE-2025-47935HIGHCVSS 7.5EG 7.5✓ Fixed in 2.0.02025-05-19
Multer is a node.js middleware for handling `multipart/form-data`. Versions prior to 2.0.0 are vulnerable to a resource exhaustion and memory leak issue due to improper stream handling. When the HTTP request stream emits an error, the inte…
- CVE-2025-47944HIGHCVSS 7.5EG 7.5✓ Fixed in 2.0.02025-05-19
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.0 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed mu…
- CVE-2025-48997NONECVSS 0.0EG 0.0✓ Fixed in 2.0.12025-06-03
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to trigger a Denial of Service (DoS) by sending an upload file…
- CVE-2025-7338HIGHCVSS 7.5EG 7.5✓ Fixed in 2.0.22025-07-17
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.2 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed mu…
Check whether multer is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for multer CVEs against the assets you own.
Start Free Scan →