Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.3
Malformed Requests Crash Multer Server Before Version 2.1.0
CVE-2026-3304
GHSA-xf7r-hgr6-v32p
CVE-2026-3304
Summary
Multer, a tool used by some website servers, can crash if it receives a specially crafted request. This can cause the server to stop working. Update Multer to the latest version to fix this issue.
What to do
- Update ulisesgascon multer to version 2.1.0.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| ulisesgascon | multer | <= 2.1.0 | 2.1.0 |
Original title
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requ...
Original description
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.
nvd CVSS4.0
8.7
Vulnerability type
CWE-459
- https://www.cve.org/CVERecord?id=CVE-2026-3304
- https://nvd.nist.gov/vuln/detail/CVE-2026-3304
- https://github.com/advisories/GHSA-xf7r-hgr6-v32p
- https://cna.openjsf.org/security-advisories.html
- https://github.com/expressjs/multer/commit/739919097dde3921ec31b930e4b9025036fa7...
- https://github.com/expressjs/multer/security/advisories/GHSA-xf7r-hgr6-v32p
- https://github.com/expressjs/multer Product
Published: 27 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026