Impact
multer, a middleware library for handling multipart form uploads in Node.js, contains a flaw in the version range 2.2.0 through 2.3.0. When a client aborts an upload that is being written to disk, malformed cleanup logic allows file writes that complete after the abort handler to persist on the filesystem. Each aborted upload can therefore leave an orphaned file behind. An attacker may repeatedly trigger this pattern to accumulate many orphaned files, ultimately exhausting available disk space and causing a denial of service for all users of the application. This vulnerability falls under CWE-400 and CWE-459, representing uncontrolled resource consumption and improper file cleanup, respectively.
Affected Systems
Any Node.js application that incorporates the multer middleware with disk storage, specifically those using multer‑2.2.0, 2.2.x, 2.3.0, or any pre‑2.4.0 release. The issue does not affect earlier releases (pre‑2.2.0) or the 2.4.0 and later versions where the bug has been fixed.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, and the EPSS score of less than 1% indicates that exploitation is unlikely but possible. The vulnerability is not listed in the CISA KEV catalog. The attack most likely occurs over the network, with an unauthenticated remote attacker initiating and aborting file uploads. Under standard operating conditions, a single attack can consume significant disk space over time, potentially bringing the service down once the storage quota is reached.
OpenCVE Enrichment
Github GHSA