multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first field uses a very large numeric array index to allocate a maximum-length sparse array, and a second field then pushes past that length, which throws inside the append-field dependency and is not caught by multer. All versions before 2.3.0 are affected, and the issue is a remotely triggerable denial of service. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Expressjs
Expressjs multer |
|
| CPEs | cpe:2.3:a:expressjs:multer:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Expressjs
Expressjs multer |
Tue, 01 Sep 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 29 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Multer
Multer multer |
|
| Vendors & Products |
Multer
Multer multer |
Fri, 28 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first field uses a very large numeric array index to allocate a maximum-length sparse array, and a second field then pushes past that length, which throws inside the append-field dependency and is not caught by multer. All versions before 2.3.0 are affected, and the issue is a remotely triggerable denial of service. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate. | |
| Title | multer vulnerable to Denial of Service via crafted multipart field names | |
| Weaknesses | CWE-248 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: openjs
Published: 2026-08-28T20:03:23.114Z
Updated: 2026-08-31T18:40:24.545Z
Reserved: 2026-08-20T10:53:48.073Z
Link: CVE-2026-77078
Updated: 2026-08-31T18:40:17.216Z
Status : Analyzed
Published: 2026-08-28T22:16:53.883
Modified: 2026-09-02T14:46:28.590
Link: CVE-2026-77078
No data.