---
id: CVE-2026-5038
title: >-
  multer: Multer: Denial of Service via aborted or malformed multipart uploads
  (CVE-2026-5038)
summary: >-
  A flaw was found in multer. This vulnerability allows a remote attacker to
  trigger a Denial of Service (DoS) by initiating and then aborting or sending
  malformed multipart uploads. This action leaves orphaned partial files on the
  disk, whi…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-772
  - CWE-459
vendor: Red Hat
product: Red Hat Enterprise Linux 10
affected:
  - logging_subsystem_for_red_hat_openshift
  - enterprise_linux 10
  - enterprise_linux 8
  - enterprise_linux 9
  - self_service_automation_portal 2
  - developer_hub 1.10
  - developer_hub 1.9
patched:
  - developer_hub 1.10
  - developer_hub 1.9
published: '2026-06-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T14:23:18+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5038.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5038.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-5038'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2488935'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-5038'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5038'
  - url: 'https://cna.openjsf.org/security-advisories.html'
  - url: >-
      https://github.com/expressjs/multer/security/advisories/GHSA-3p4h-7m6x-2hcm
  - url: 'https://access.redhat.com/errata/RHSA-2026:48126'
  - url: 'https://access.redhat.com/errata/RHSA-2026:49642'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52768'
  - url: 'https://github.com/advisories/GHSA-3p4h-7m6x-2hcm'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
  - score-dispute
epss: 0.00488
epssPercentile: 0.394
ecosystem: npm
scores:
  vendor: 7.5
  ghsa: 5.3
ingestedAt: '2026-06-29T14:31:47.221Z'
---

## Overview

A flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, which can lead to the exhaustion of available disk space without requiring any specific application bug.

## Vendor advisories

- **RHSA-2026:48126** · Red Hat · fixed in: Red Hat Developer Hub 1.10 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48126)
- **RHSA-2026:49642** · Red Hat · fixed in: Red Hat Developer Hub 1.10 · released 2026-08-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:49642)
- **RHSA-2026:52768** · Red Hat · fixed in: Red Hat Developer Hub 1.9 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52768)
- **Red Hat VEX** · Important · affected: Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Self-service automation portal 2 · no fix planned: Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5038.json)

**multer: Multer: Denial of Service via aborted or malformed multipart uploads** — rated Important by Red Hat. Released 2026-06-15, updated 2026-09-21.

Affected:

- Logging Subsystem for Red Hat OpenShift
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Self-service automation portal 2

Fixed:

- Red Hat Developer Hub 1.10
- Red Hat Developer Hub 1.9

No fix planned:

- Logging Subsystem for Red Hat OpenShift
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Self-service automation portal 2

Not affected:

- Red Hat Developer Hub 1.10
- Red Hat Developer Hub 1.9
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 9
- Red Hat Trusted Profile Analyzer

## Remediation

For more about Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:48126
For more about Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:49642
For more about Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:52768

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-5038)

Affected packages:

- `multer >= 2.0.0-alpha.1, < 2.2.0`
- `multer >= 3.0.0-alpha.1, < 3.0.0-alpha.2`

Patched in:

- `multer 2.2.0`
- `multer 3.0.0-alpha.2`

Source: https://github.com/advisories/GHSA-3p4h-7m6x-2hcm
