Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

multer — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in multer, with AI-generated Chinese analysis, references, and POCs.

Vendor: expressjs

CVE ID Title CVSS Severity Published
CVE-2026-88932 multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads CWE-400 5.3 Medium 2026-09-14
CVE-2026-82333 multer vulnerable to Denial of Service via oversized array index in field names CWE-400 7.5 High 2026-08-28
CVE-2026-77078 multer vulnerable to Denial of Service via crafted multipart field names CWE-248 7.5 High 2026-08-28
CVE-2026-77063 multer vulnerable to file size limit bypass via async fileFilter race condition CWE-362 3.7 Low 2026-08-28
CVE-2026-77037 multer vulnerable to Denial of Service via file descriptor leak on aborted uploads CWE-400 7.5 High 2026-08-28
CVE-2026-5038 multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads CWE-459 5.3 Medium 2026-06-15
CVE-2026-5079 multer vulnerable to Denial of Service via deeply nested field names CWE-400 7.5 High 2026-06-15
CVE-2026-3520 Multer vulnerable to Denial of Service via uncontrolled recursion CWE-674 7.5 - 2026-03-04
CVE-2026-3304 Multer vulnerable to Denial of Service via incomplete cleanup CWE-459 7.5 - 2026-02-27
CVE-2026-2359 Multer vulnerable to Denial of Service via resource exhaustion CWE-772 7.5 - 2026-02-27
CVE-2025-7338 Multer vulnerable to Denial of Service via unhandled exception from malformed request CWE-248 7.5 High 2025-07-17
CVE-2025-48997 Multer vulnerable to Denial of Service via unhandled exception CWE-248 7.5 - 2025-06-03
CVE-2025-47944 Multer vulnerable to Denial of Service from maliciously crafted requests CWE-248 7.5 High 2025-05-19
CVE-2025-47935 Multer vulnerable to Denial of Service via memory leaks from unclosed streams CWE-401 7.5 High 2025-05-19

All 14 known CVE vulnerabilities affecting multer with full Chinese analysis, references, and POCs where available.