CVE-2026-5038High· 7.5▾ TwilightA flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, whi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
Last analysed / modified upstream
5.3 → 7.5
medium → high
A flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, which can lead to the exhaustion of available disk space without requiring any specific application bug.
multer: Multer: Denial of Service via aborted or malformed multipart uploads — rated Important by Red Hat. Released 2026-06-15, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more about Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:48126 For more about Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:49642 For more about Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:52768
Workarounds / mitigations:
Affected packages:
multer >= 2.0.0-alpha.1, < 2.2.0multer >= 3.0.0-alpha.1, < 3.0.0-alpha.2Patched in:
multer 2.2.0multer 3.0.0-alpha.2Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-5079High· 7.5multer: Multer: Denial of Service via deeply nested field names in multipart form data (CVE-2026-5079)
CVE-2026-89681High· 7.0kernel: nfsd: fix layout fence worker double-reference race (CVE-2026-89681)
CVE-2026-54876High· 7.5Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…
CVE-2026-88932Medium· 5.3multer is a Node.js middleware for handling multipart/form-data uploads
CVE-2026-80988Medium· 5.5kernel: NTB: ntb_transport: Fail TX enqueue when the QP link is down (CVE-2026-80988)
CVE-2026-89529High· 7.0kernel: svcrdma: Reject oversized Read segments at decode time (CVE-2026-89529)