THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wc9g-mqfw-jrwm (high) — multer vulnerable to Denial of Service via crafted multipart field names

[GHSA] GHSA-wc9g-mqfw-jrwm (high) — multer vulnerable to Denial of Service via crafted multipart field names

medgithub_advisoriesPublished 2026-09-08

GHSA-wc9g-mqfw-jrwm Severity: high CVE: CVE-2026-77078

multer vulnerable to Denial of Service via crafted multipart field names

### Impact

A vulnerability in multer allows a remote, unauthenticated attacker to crash the Node.js process with a single `multipart/form-data` request. Two specially crafted text field names cause an uncaught `RangeError: Invalid array length` inside multer's field pa

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wc9g-mqfw-jrwm