GHSA-wc9g-mqfw-jrwm
Dashboard / Vulnerabilities / GHSA-wc9g-mqfw-jrwm
Summary: multer vulnerable to Denial of Service via crafted multipart field names
Details: ### Impact A vulnerability in multer allows a remote, unauthenticated attacker to crash the Node.js process with a single `multipart/form-data` request. Two specially crafted text field names cause an uncaught `RangeError: Invalid array length` inside multer's field parsing, which is not routed to the application error handler and terminates the process. All applications using multer to parse multipart requests are affected. ### Patches Users should upgrade to `2.3.0`. ### Workarounds None.
References: https://github.com/expressjs/multer/security/advisories/GHSA-wc9g-mqfw-jrwm, https://nvd.nist.gov/vuln/detail/CVE-2026-77078, https://github.com/expressjs/multer/commit/87a584e8c8d4da873292635fa1d8c4d78d985b76, https://cna.openjsf.org/security-advisories.html, https://github.com/expressjs/multer, https://github.com/expressjs/multer/releases/tag/v2.3.0
Affected packages
Package
Name: multer
Purl: pkg:npm/multer
Affected ranges
Type: SEMVER
Events:
