UNKNOWN npm

Multer vulnerable to Denial of Service via incomplete cleanup

GHSA-xf7r-hgr6-v32p · CVE-2026-3304

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion.

Patches

Users should upgrade to 2.1.0

Workarounds

None

Ready to move

Start Securing

Free, no credit card | First findings in minutes