PT-2026-91122 · Npm · Multer

·

CVE-2026-88932

·

Published

2026-09-14

·

Updated

2026-09-28

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions multer versions 2.2.0 through 2.3.0
Description multer is a Node.js middleware for handling multipart/form-data uploads. When a request using disk storage is aborted during the upload process, file writes that finish after the abort cleanup has executed are not deleted. This results in orphaned files remaining on the disk. A remote unauthenticated attacker can exploit this by repeatedly starting and aborting uploads to fill the disk space, leading to a denial of service.
Recommendations Upgrade multer to version 2.4.0 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88932
GHSA-3PPH-FPJX-JG34

Affected Products

Multer