THREAT OPS › Threat News › [GHSA] GHSA-qfvm-cv95-jqjf (high) — multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
[GHSA] GHSA-qfvm-cv95-jqjf (high) — multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
GHSA-qfvm-cv95-jqjf Severity: high CVE: CVE-2026-77037
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
### Impact
A vulnerability in multer `2.2.0` allows an attacker to trigger a Denial of Service (DoS) by aborting or truncating multipart uploads. When using `diskStorage`, the destination write stream is not closed if the upload is aborted before it finishes,
Indicators of compromise
- CVE-2026-77037cve
Original source: https://github.com/advisories/GHSA-qfvm-cv95-jqjf