Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to trigger a Denial of Service (DoS) by sending an upload file request with an empty string field name. This request causes an unhandled exception, leading to a crash of the process. Users should upgrade to `2.0.1` to receive a patch. No known workarounds are available.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-16780 Multer vulnerable to Denial of Service via unhandled exception
Github GHSA Github GHSA GHSA-g5hg-p3ph-g8qg Multer vulnerable to Denial of Service via unhandled exception
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 06 Jun 2025 19:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


Tue, 03 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Jun 2025 18:30:00 +0000

Type Values Removed Values Added
Description Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker to trigger a Denial of Service (DoS) by sending an upload file request with an empty string field name. This request causes an unhandled exception, leading to a crash of the process. Users should upgrade to `2.0.1` to receive a patch. No known workarounds are available.
Title Multer vulnerable to Denial of Service via unhandled exception
Weaknesses CWE-248
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-06-03T18:30:13.178Z

Reserved: 2025-05-29T16:34:07.174Z

Link: CVE-2025-48997

cve-icon Vulnrichment

Updated: 2025-06-03T18:30:02.885Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-03T19:15:39.577

Modified: 2025-06-04T14:54:33.783

Link: CVE-2025-48997

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-06-03T18:21:59Z

Links: CVE-2025-48997 - Bugzilla

cve-icon OpenCVE Enrichment

No data.