๐Ÿ” CVE Alert

CVE-2026-3520

UNKNOWN 0.0

Multer vulnerable to Denial of Service via uncontrolled recursion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. Users should upgrade to version 2.1.1 to receive a patch. No known workarounds are available.

CWE CWE-674
Vendor expressjs
Product multer
Published Mar 4, 2026
Last Updated Mar 4, 2026
Stay Ahead of the Next One

Get instant alerts for expressjs multer

Be the first to know when new unknown vulnerabilities affecting expressjs multer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

expressjs / multer
0 < 2.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/expressjs/multer/security/advisories/GHSA-5528-5vmv-3xc2 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-3520 github.com: https://github.com/expressjs/multer/commit/7e66481f8b2e6c54b982b34c152479e096ce2752 cna.openjsf.org: https://cna.openjsf.org/security-advisories.html

Credits

๐Ÿ” Yuki Matsuhashi Chris de Almeida Ulises Gascรณn