VYPR
High severity7.5NVD Advisory· Published Jun 15, 2026· Updated Jun 16, 2026

CVE-2026-5079

CVE-2026-5079

Description

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this.

Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease) and configure the new limits.fieldNestingDepth option to the minimum depth their application requires.

Workarounds: Set limits.fields to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
multernpm
>= 1.0.0, < 2.2.02.2.0
multernpm
>= 3.0.0-alpha.1, < 3.0.0-alpha.23.0.0-alpha.2

Affected products

3
  • Expressjs/Multerinferred2 versions
    = 3.0.0-alpha.1+ 1 more
    • (no CPE)range: = 3.0.0-alpha.1
    • (no CPE)range: >=1.0.0 <=2.1.1, >=3.0.0-alpha.1 <3.0.0-alpha.2
  • ghsa-coords
    Range: >= 1.0.0, < 2.2.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.