Multer vulnerable to Denial of Service via incomplete cleanup
Description
Published by the National Vulnerability Database
Feb 27, 2026
Published to the GitHub Advisory Database
Mar 1, 2026
Reviewed
Mar 1, 2026
Last updated
Mar 1, 2026
Impact
A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion.
Patches
Users should upgrade to
2.1.0Workarounds
None
References