Skip to content

chore(deps): update dependency multer to v2.3.0 [security] - #1883

Merged
renovate[bot] merged 1 commit into
masterfrom
renovate/npm-multer-vulnerability
Sep 11, 2026
Merged

renovate[bot] merged 1 commit into
masterfrom
renovate/npm-multer-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
multer 2.2.0 → 2.3.0 age confidence

multer vulnerable to Denial of Service via file descriptor leak on aborted uploads

CVE-2026-77037 / GHSA-qfvm-cv95-jqjf

More information

Details

Impact

A vulnerability in multer 2.2.0 allows an attacker to trigger a Denial of Service (DoS) by aborting or truncating multipart uploads. When using diskStorage, the destination write stream is not closed if the upload is aborted before it finishes, so each failed request leaks an open file descriptor and retains its disk blocks until the process exits. Repeated failed uploads can exhaust the available file descriptors. All applications using multer's disk storage are affected.

Patches

Users should upgrade to 2.3.0.

Workarounds

None.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


multer vulnerable to Denial of Service via oversized array index in field names

CVE-2026-82333 / GHSA-535w-7cp7-47q4

More information

Details

Impact

multer is vulnerable to a Denial of Service (DoS) via a crafted array index in multipart field names. The append-field dependency parses bracket notation in field names, and a large numeric index such as items[4294967294] forces allocation of a maximum-length sparse array. A following field with a non-numeric key on the same base then converts that array to an object by iterating its full length, which consumes CPU synchronously and leaves the process unable to handle other requests. A single HTTP request with a crafted multipart body is sufficient to exploit this, and it affects multer 1.x and 2.x.

Patches

Users should upgrade to 2.3.0 and configure limits.fieldArrayIndexLimit to the minimum array index their application requires.

Workarounds

None.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


multer vulnerable to file size limit bypass via async fileFilter race condition

CVE-2026-77063 / GHSA-qvfw-j98x-7q72

More information

Details

Impact

When multer is configured with an asynchronous fileFilter, the limits.fileSize limit can be bypassed. The 'limit' event is registered inside the async fileFilter callback, so if a file exceeds limits.fileSize before that callback runs, the event is missed and the oversized upload is accepted instead of being rejected with a LIMIT_FILE_SIZE error. Applications that rely on limits.fileSize to reject oversized uploads are affected on all upload methods (.single(), .array(), .fields(), .any()). Uploads using a synchronous fileFilter are not affected.

Patches

Users should upgrade to 2.3.0.

Workarounds

Use a synchronous fileFilter, or validate the uploaded file size after the upload completes.

Severity

  • CVSS Score: 3.7 / 10 (Low)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


multer vulnerable to Denial of Service via crafted multipart field names

CVE-2026-77078 / GHSA-wc9g-mqfw-jrwm

More information

Details

Impact

A vulnerability in multer allows a remote, unauthenticated attacker to crash the Node.js process with a single multipart/form-data request. Two specially crafted text field names cause an uncaught RangeError: Invalid array length inside multer's field parsing, which is not routed to the application error handler and terminates the process. All applications using multer to parse multipart requests are affected.

Patches

Users should upgrade to 2.3.0.

Workarounds

None.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

expressjs/multer (multer)

v2.3.0

Compare Source


Configuration

📅 Schedule: (in timezone Europe/London)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@sonarqubecloud

Copy link
Copy Markdown

@cypress

cypress Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

BanManager-WebUI    Run #11479

Run Properties:  status check passed Passed #11479  •  git commit 43b4f5b049 ℹ️: Merge 5c031b6f9bd42ec520dc4a33bd30b1937d603b4e into 86006146afbe034ea05db9bb08c3...
Project BanManager-WebUI
Branch Review renovate/npm-multer-vulnerability
Run status status check passed Passed #11479
Run duration 02m 12s
Commit git commit 43b4f5b049 ℹ️: Merge 5c031b6f9bd42ec520dc4a33bd30b1937d603b4e into 86006146afbe034ea05db9bb08c3...
Committer renovate[bot]
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 1
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 49
View all changes introduced in this branch ↗︎

@renovate
renovate Bot merged commit 675e186 into master Sep 11, 2026
10 checks passed
@renovate
renovate Bot deleted the renovate/npm-multer-vulnerability branch September 11, 2026 00:10
@cypress

cypress Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

BanManager-WebUI    Run #11482

Run Properties:  status check passed Passed #11482  •  git commit 675e186b22: chore(deps): update dependency multer to v2.3.0 [security] (#1883)
Project BanManager-WebUI
Branch Review master
Run status status check passed Passed #11482
Run duration 02m 18s
Commit git commit 675e186b22: chore(deps): update dependency multer to v2.3.0 [security] (#1883)
Committer renovate[bot]
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 1
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 49
View all changes introduced in this branch ↗︎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants