MEDIUM 5.3 npm

Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads

GHSA-3p4h-7m6x-2hcm · CVE-2026-5038

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

A vulnerability in Multer allows an attacker to trigger a Denial of Service (DoS) by aborting or sending malformed multipart uploads, causing orphaned partial files to accumulate on disk when using diskStorage.

Patches

Users should upgrade to 2.2.0, 3.0.0-alpha.2 or higher

Workarounds

None

Ready to move

Start Securing

Free, no credit card | First findings in minutes