CVE-2026-88932 PUBLISHED

multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads

Assigner: openjs
Reserved: 10.09.2026 Published: 14.09.2026 Updated: 14.09.2026

multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A remote unauthenticated attacker can repeatedly start and abort uploads to accumulate orphaned files and exhaust disk space, causing a denial of service. The issue is fixed in multer 2.4.0, and users should upgrade to 2.4.0 or later.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 5.3

Product Status

Vendor multer
Product multer
Versions Default: unaffected
  • affected from 2.2.0 to 2.4.0 (excl.)
  • Version 2.4.0 is unaffected

Credits

  • euriconicacio reporter
  • UlisesGascon remediation developer
  • bjohansebas remediation reviewer

References

Problem Types

  • CWE-400: Uncontrolled Resource Consumption CWE
  • CWE-459: Incomplete Cleanup CWE