GHSA-wc9g-mqfw-jrwm

Suggest an improvement
Source
https://github.com/advisories/GHSA-wc9g-mqfw-jrwm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wc9g-mqfw-jrwm/GHSA-wc9g-mqfw-jrwm.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-wc9g-mqfw-jrwm
Aliases
Downstream
MINI (4)
Published
2026-09-08T21:30:20Z
Modified
2026-09-08T21:45:04Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
multer vulnerable to Denial of Service via crafted multipart field names
Details

Impact

A vulnerability in multer allows a remote, unauthenticated attacker to crash the Node.js process with a single multipart/form-data request. Two specially crafted text field names cause an uncaught RangeError: Invalid array length inside multer's field parsing, which is not routed to the application error handler and terminates the process. All applications using multer to parse multipart requests are affected.

Patches

Users should upgrade to 2.3.0.

Workarounds

None.

Database specific
{
    "cwe_ids": [
        "CWE-248"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-08T21:30:20Z",
    "nvd_published_at": "2026-08-28T22:16:53Z",
    "severity": "HIGH"
}
References

Affected packages

npm / multer

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wc9g-mqfw-jrwm/GHSA-wc9g-mqfw-jrwm.json"