VDB
Sign up
HIGH

GHSA-v52c-386h-88mc

Multer vulnerable to Denial of Service via resource exhaustion

Quick fix

GHSA-v52c-386h-88mc — multer: upgrade to the fixed version with the command below.

npm install multer@2.1.0

Details

### Impact

A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing resource exhaustion.

### Patches

Users should upgrade to `2.1.0`

### Workarounds

None

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/multer
Introduced in: 0Fixed in: 2.1.0
Fixnpm install multer@2.1.0

References