multer has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 7.5 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-82333High· 7.5multer vulnerable to Denial of Service via oversized array index in field names41CVE-2026-77078High· 7.5multer vulnerable to Denial of Service via crafted multipart field names41CVE-2026-77037High· 7.5multer vulnerable to Denial of Service via file descriptor leak on aborted uploads41CVE-2026-77063Low· 3.7multer vulnerable to file size limit bypass via async fileFilter race condition20
multer vulnerabilities
CVEs affecting multer, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-82333High· 7.5multer vulnerable to Denial of Service via oversized array index in field names
multer vulnerable to Denial of Service via oversized array index in field names
▾ Twilightmulter · multerEPSS 0.28%via GHSA
CVE-2026-77078High· 7.5multer vulnerable to Denial of Service via crafted multipart field names
multer vulnerable to Denial of Service via crafted multipart field names
▾ Twilightmulter · multerEPSS 0.29%via GHSA
CVE-2026-77063Low· 3.7multer vulnerable to file size limit bypass via async fileFilter race condition
multer vulnerable to file size limit bypass via async fileFilter race condition
▾ Sunlitmulter · multerEPSS 0.16%via GHSA
CVE-2026-77037High· 7.5multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
▾ Twilightmulter · multerEPSS 0.35%via GHSA