Skip to main content

Vendor/product archive

expressjs / multer CVEs

Beta · best-effort

5 CVEs tagged to expressjs / multer0 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-5038

Published Jun 15, 2026

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave or…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-5079

Published Jun 15, 2026

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependen…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-3520

Published Mar 4, 2026

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by send…

CVSS 8.7 · High
evidence mentions
9
Buzz score
42.5
Vendor/product tagsBeta · best-effort

CVE-2026-3304

Published Feb 27, 2026

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by send…

CVSS 8.7 · High
evidence mentions
9
Buzz score
42.5
Vendor/product tagsBeta · best-effort

CVE-2026-2359

Published Feb 27, 2026

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by drop…

CVSS 8.7 · High
evidence mentions
9
Buzz score
42.5
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1