A vulnerability in Multer allows an attacker to trigger a Denial of Service (DoS) by aborting or sending malformed multipart uploads, causing orphaned partial files to accumulate on disk when using diskStorage.
Users should upgrade to 2.2.0, 3.0.0-alpha.2 or higher
None
{
"cwe_ids": [
"CWE-459"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-17T18:11:48Z",
"nvd_published_at": "2026-06-15T16:16:34Z",
"severity": "MODERATE"
}