Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3p4h-7m6x-2hcm

Опубликовано: 17 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads

Impact

A vulnerability in Multer allows an attacker to trigger a Denial of Service (DoS) by aborting or sending malformed multipart uploads, causing orphaned partial files to accumulate on disk when using diskStorage.

Patches

Users should upgrade to 2.2.0, 3.0.0-alpha.2 or higher

Workarounds

None

Пакеты

Наименование

multer

npm
Затронутые версииВерсия исправления

>= 2.0.0-alpha.1, < 2.2.0

2.2.0

Наименование

multer

npm
Затронутые версииВерсия исправления

>= 3.0.0-alpha.1, < 3.0.0-alpha.2

3.0.0-alpha.2

EPSS

Процентиль: 20%
0.00278
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-459

Связанные уязвимости

CVSS3: 7.5
redhat
около 2 месяцев назад

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required. Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight write streams and clean them up on the abort path. Workarounds: None.

CVSS3: 5.3
nvd
около 2 месяцев назад

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required. Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight write streams and clean them up on the abort path. Workarounds: None.

EPSS

Процентиль: 20%
0.00278
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-459