Medium severity5.3NVD Advisory· Published Sep 14, 2026· Updated Sep 14, 2026
CVE-2026-88932
CVE-2026-88932
Description
multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A remote unauthenticated attacker can repeatedly start and abort uploads to accumulate orphaned files and exhaust disk space, causing a denial of service. The issue is fixed in multer 2.4.0, and users should upgrade to 2.4.0 or later.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.