{"id":"CVE-2026-5038","title":"multer: Multer: Denial of Service via aborted or malformed multipart uploads (CVE-2026-5038)","summary":"A flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, whi…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-772","CWE-459"],"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["logging_subsystem_for_red_hat_openshift","enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","self_service_automation_portal 2","developer_hub 1.10","developer_hub 1.9"],"patched":["developer_hub 1.10","developer_hub 1.9"],"published":"2026-06-15","updated":"2026-09-21","sourceUpdated":"2026-09-21T14:23:18+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5038.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5038.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-5038"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488935"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-5038"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5038"},{"url":"https://cna.openjsf.org/security-advisories.html"},{"url":"https://github.com/expressjs/multer/security/advisories/GHSA-3p4h-7m6x-2hcm"},{"url":"https://access.redhat.com/errata/RHSA-2026:48126"},{"url":"https://access.redhat.com/errata/RHSA-2026:49642"},{"url":"https://access.redhat.com/errata/RHSA-2026:52768"},{"url":"https://github.com/advisories/GHSA-3p4h-7m6x-2hcm"}],"tags":["csaf","vex","red-hat","ghsa","npm","score-dispute"],"epss":0.00278,"epssPercentile":0.20524,"ecosystem":"npm","scores":{"vendor":7.5,"ghsa":5.3},"ingestedAt":"2026-06-29T14:31:47.221Z","slug":"CVE-2026-5038","body":"## Overview\n\nA flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, which can lead to the exhaustion of available disk space without requiring any specific application bug.\n\n## Vendor advisories\n\n- **RHSA-2026:48126** · Red Hat · fixed in: Red Hat Developer Hub 1.10 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48126)\n- **RHSA-2026:49642** · Red Hat · fixed in: Red Hat Developer Hub 1.10 · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49642)\n- **RHSA-2026:52768** · Red Hat · fixed in: Red Hat Developer Hub 1.9 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52768)\n- **Red Hat VEX** · Important · affected: Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Self-service automation portal 2 · no fix planned: Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5038.json)\n\n**multer: Multer: Denial of Service via aborted or malformed multipart uploads** — rated Important by Red Hat. Released 2026-06-15, updated 2026-09-21.\n\nAffected:\n\n- Logging Subsystem for Red Hat OpenShift\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Self-service automation portal 2\n\nFixed:\n\n- Red Hat Developer Hub 1.10\n- Red Hat Developer Hub 1.9\n\nNo fix planned:\n\n- Logging Subsystem for Red Hat OpenShift\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Self-service automation portal 2\n\nNot affected:\n\n- Red Hat Developer Hub 1.10\n- Red Hat Developer Hub 1.9\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 9\n- Red Hat Trusted Profile Analyzer\n\n## Remediation\n\nFor more about Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:48126\nFor more about Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:49642\nFor more about Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:52768\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-5038)\n\nAffected packages:\n\n- `multer >= 2.0.0-alpha.1, < 2.2.0`\n- `multer >= 3.0.0-alpha.1, < 3.0.0-alpha.2`\n\nPatched in:\n\n- `multer 2.2.0`\n- `multer 3.0.0-alpha.2`\n\nSource: https://github.com/advisories/GHSA-3p4h-7m6x-2hcm","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208446,"id":"CVE-2026-5038","ts":1790005704950,"field":"cvss","old":"5.3","new":"7.5"},{"seq":208445,"id":"CVE-2026-5038","ts":1790005704950,"field":"severity","old":"medium","new":"high"}]}