Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5038

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required. Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight write streams and clean them up on the abort path. Workarounds: None.

A flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, which can lead to the exhaustion of available disk space without requiring any specific application bug.

Отчет

This is an Important denial of service vulnerability in multer when configured to use diskStorage. An attacker can exploit this flaw by initiating and then aborting or sending malformed multipart uploads, leading to the accumulation of orphaned partial files and eventual disk space exhaustion on affected Red Hat products that utilize multer for file handling.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Affected
Red Hat Enterprise Linux 10fido-device-onboardAffected
Red Hat Enterprise Linux 10firefoxAffected
Red Hat Enterprise Linux 10thunderbirdAffected
Red Hat Enterprise Linux 7firefoxAffected
Red Hat Enterprise Linux 8thunderbirdAffected
Red Hat Enterprise Linux 9firefoxAffected
Red Hat Enterprise Linux 9thunderbirdAffected
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Not affected
Self-service automation portal 2ansible-automation-platform/automation-portalAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2488935multer: Multer: Denial of Service via aborted or malformed multipart uploads

EPSS

Процентиль: 21%
0.00278
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required. Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight write streams and clean them up on the abort path. Workarounds: None.

CVSS3: 5.3
github
3 месяца назад

Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads

EPSS

Процентиль: 21%
0.00278
Низкий

7.5 High

CVSS3