Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88932

Опубликовано: 14 сент. 2026
Источник: redhat
CVSS3: 5.3

Описание

multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A remote unauthenticated attacker can repeatedly start and abort uploads to accumulate orphaned files and exhaust disk space, causing a denial of service. The issue is fixed in multer 2.4.0, and users should upgrade to 2.4.0 or later.

A flaw was found in multer, a Node.js middleware for handling multipart/form-data uploads. When a request using disk storage is aborted during an upload, file writes that complete after multer's cleanup process are not removed. This can leave orphaned files on disk. A remote unauthenticated attacker can repeatedly initiate and abort uploads to accumulate these orphaned files, which can exhaust disk space and lead to a denial of service.

Отчет

This Moderate flaw in multer can lead to a denial of service in Red Hat products that process multipart/form-data uploads. A remote unauthenticated attacker can repeatedly initiate and abort uploads, causing orphaned files to accumulate and exhaust available disk space. This risk is present in deployments where multer is configured for disk storage.

Меры по смягчению последствий

To reduce the attack surface, restrict network access to services utilizing multer for file uploads to trusted clients or internal networks where feasible. Implement rate limiting on upload endpoints to mitigate the impact of repeated, aborted uploads. Regularly monitor disk space on systems hosting affected applications to detect and address potential exhaustion due to orphaned files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Not affected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backendAffected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backendAffected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Affected
Self-service automation portal 2ansible-automation-platform/automation-portalAffected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-459
https://bugzilla.redhat.com/show_bug.cgi?id=2532957multer: multer: Denial of Service via orphaned disk writes on aborted uploads

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
9 дней назад

multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A remote unauthenticated attacker can repeatedly start and abort uploads to accumulate orphaned files and exhaust disk space, causing a denial of service. The issue is fixed in multer 2.4.0, and users should upgrade to 2.4.0 or later.

5.3 Medium

CVSS3

Уязвимость CVE-2026-88932