Description
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first field uses a very large numeric array index to allocate a maximum-length sparse array, and a second field then pushes past that length, which throws inside the append-field dependency and is not caught by multer. All versions before 2.3.0 are affected, and the issue is a remotely triggerable denial of service. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate.
Published: 2026-08-28
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A small multipart/form-data request containing two specially crafted text field names can trigger an uncaught RangeError in the Multer middleware, causing the Node.js process to terminate. This occurs when the first field uses a very large numeric array index that allocates a maximum-length sparse array, and the second field pushes past that length in the append‑field dependency, which is not caught by Multer. The resulting process crash results in a denial of service for the application without authentication or privileged access.

Affected Systems

The vulnerability affects the Multer middleware for Express in Node.js. All Multer versions prior to 2.3.0 are susceptible. It is relevant to any deployment that uses Multer to handle multipart/form-data.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack can be performed remotely by sending a crafted multipart request to any public or internal endpoint that processes multipart/form-data. No special permissions are required; once the RangeError is triggered the application process terminates, leading to service interruption.

Generated by OpenCVE AI on August 28, 2026 at 23:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Multer to version 2.3.0 or later, which contains the fix for the RangeError bug.
  • Restart or monitor the Node.js process so that it recovers automatically after a crash, reducing the window for downtime.
  • Validate or sanitize multipart field names before they reach Multer to ensure numeric indices are within safe bounds, preventing the same type of array overflow.

Generated by OpenCVE AI on August 28, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Multer
Multer multer
Vendors & Products Multer
Multer multer

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first field uses a very large numeric array index to allocate a maximum-length sparse array, and a second field then pushes past that length, which throws inside the append-field dependency and is not caught by multer. All versions before 2.3.0 are affected, and the issue is a remotely triggerable denial of service. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate.
Title multer vulnerable to Denial of Service via crafted multipart field names
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-08-28T20:03:23.114Z

Reserved: 2026-08-20T10:53:48.073Z

Link: CVE-2026-77078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:53.883

Modified: 2026-08-28T22:16:53.883

Link: CVE-2026-77078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:05Z

Weaknesses