Description
multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A remote unauthenticated attacker can repeatedly start and abort uploads to accumulate orphaned files and exhaust disk space, causing a denial of service. The issue is fixed in multer 2.4.0, and users should upgrade to 2.4.0 or later.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via orphaned disk writes
Action: Immediate Patch
AI Analysis

Impact

multer, a middleware library for handling multipart form uploads in Node.js, contains a flaw in the version range 2.2.0 through 2.3.0. When a client aborts an upload that is being written to disk, malformed cleanup logic allows file writes that complete after the abort handler to persist on the filesystem. Each aborted upload can therefore leave an orphaned file behind. An attacker may repeatedly trigger this pattern to accumulate many orphaned files, ultimately exhausting available disk space and causing a denial of service for all users of the application. This vulnerability falls under CWE-400 and CWE-459, representing uncontrolled resource consumption and improper file cleanup, respectively.

Affected Systems

Any Node.js application that incorporates the multer middleware with disk storage, specifically those using multer‑2.2.0, 2.2.x, 2.3.0, or any pre‑2.4.0 release. The issue does not affect earlier releases (pre‑2.2.0) or the 2.4.0 and later versions where the bug has been fixed.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity, and the EPSS score of less than 1% indicates that exploitation is unlikely but possible. The vulnerability is not listed in the CISA KEV catalog. The attack most likely occurs over the network, with an unauthenticated remote attacker initiating and aborting file uploads. Under standard operating conditions, a single attack can consume significant disk space over time, potentially bringing the service down once the storage quota is reached.

Generated by OpenCVE AI on September 15, 2026 at 14:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the multer middleware to version 2.4.0 or newer, which removes the orphaned file cleanup flaw.
  • If an upgrade is not immediately possible, switch to an in‑memory storage strategy for uploads or implement a post‑abort cleanup routine that deletes any partially written files.
  • Configure disk quotas or actively monitor free disk space on the node to trigger alerts when usage is approaching capacity, thereby preventing a full denial of service before disk exhaustion occurs.

Generated by OpenCVE AI on September 15, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3pph-fpjx-jg34 multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
History

Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Multer
Multer multer
Vendors & Products Multer
Multer multer

Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A remote unauthenticated attacker can repeatedly start and abort uploads to accumulate orphaned files and exhaust disk space, causing a denial of service. The issue is fixed in multer 2.4.0, and users should upgrade to 2.4.0 or later.
Title multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
Weaknesses CWE-400
CWE-459
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-09-14T10:29:12.674Z

Reserved: 2026-09-10T14:28:44.035Z

Link: CVE-2026-88932

cve-icon Vulnrichment

Updated: 2026-09-14T10:29:07.190Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T09:17:01.630

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-88932

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-14T08:46:12Z

Links: CVE-2026-88932 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:00:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-459

    Incomplete Cleanup