THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qfvm-cv95-jqjf (high) — multer vulnerable to Denial of Service via file descriptor leak on aborted uploads

[GHSA] GHSA-qfvm-cv95-jqjf (high) — multer vulnerable to Denial of Service via file descriptor leak on aborted uploads

medgithub_advisoriesPublished 2026-09-08

GHSA-qfvm-cv95-jqjf Severity: high CVE: CVE-2026-77037

multer vulnerable to Denial of Service via file descriptor leak on aborted uploads

### Impact

A vulnerability in multer `2.2.0` allows an attacker to trigger a Denial of Service (DoS) by aborting or truncating multipart uploads. When using `diskStorage`, the destination write stream is not closed if the upload is aborted before it finishes,

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qfvm-cv95-jqjf