MEDIUM 5.3 npm
Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
GHSA-3p4h-7m6x-2hcm · CVE-2026-5038
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
A vulnerability in Multer allows an attacker to trigger a Denial of Service (DoS) by aborting or sending malformed multipart uploads, causing orphaned partial files to accumulate on disk when using diskStorage.
Patches
Users should upgrade to 2.2.0, 3.0.0-alpha.2 or higher
Workarounds
None
Ready to move
Start Securing
Free, no credit card | First findings in minutes