Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-7338

Опубликовано: 17 июл. 2025
Источник: redhat
CVSS3: 5.3

Описание

Multer is a node.js middleware for handling multipart/form-data. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.2 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed multi-part upload request. This request causes an unhandled exception, leading to a crash of the process. Users should upgrade to version 2.0.2 to receive a patch. No known workarounds are available.

A denial of service vulnerability was found in the Multer NPM library. This vulnerability allows an attacker to trigger a denial of service (DoS) by sending a malformed multi-part upload request. This request causes an unhandled exception, resulting in a process crash.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Serverlessopenshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8Will not fix
Red Hat Developer Hubrhdh/rhdh-rhel9-operatorNot affected
Red Hat Developer Hub 1.7registry.redhat.io/rhdh/rhdh-hub-rhel9FixedRHSA-2025:1409019.08.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-248

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
7 месяцев назад

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.2 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed multi-part upload request. This request causes an unhandled exception, leading to a crash of the process. Users should upgrade to version 2.0.2 to receive a patch. No known workarounds are available.

CVSS3: 7.5
github
7 месяцев назад

Multer vulnerable to Denial of Service via unhandled exception from malformed request

5.3 Medium

CVSS3