Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5038

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required. Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight write streams and clean them up on the abort path. Workarounds: None.

A flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, which can lead to the exhaustion of available disk space without requiring any specific application bug.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Under investigation
Red Hat Enterprise Linux 10fido-device-onboardUnder investigation
Red Hat Enterprise Linux 10firefoxUnder investigation
Red Hat Enterprise Linux 10thunderbirdUnder investigation
Red Hat Enterprise Linux 7firefoxUnder investigation
Red Hat Enterprise Linux 8thunderbirdUnder investigation
Red Hat Enterprise Linux 9firefoxUnder investigation
Red Hat Enterprise Linux 9thunderbirdUnder investigation
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Not affected
Self-service automation portal 2ansible-automation-platform/automation-portalUnder investigation

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2488935multer: Multer: Denial of Service via aborted or malformed multipart uploads

EPSS

Процентиль: 20%
0.00278
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 месяцев назад

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required. Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight write streams and clean them up on the abort path. Workarounds: None.

CVSS3: 5.3
github
около 2 месяцев назад

Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads

EPSS

Процентиль: 20%
0.00278
Низкий

7.5 High

CVSS3