๐Ÿ” CVE Alert

CVE-2026-82333

HIGH 7.5

multer vulnerable to Denial of Service via oversized array index in field names

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop so the process cannot handle other requests. A large numeric array index in the first field allocates a maximum-length sparse array, and a second field with a non-numeric key then triggers a full-length iteration inside the append-field dependency. All versions before 2.3.0 are affected, and this is a remotely triggerable denial of service. multer 2.3.0 adds an opt-in fieldArrayIndexLimit option that rejects oversized array indexes. Upgrade to multer 2.3.0 and set limits.fieldArrayIndexLimit to the largest array index your application needs to remediate.

CWE CWE-400
Vendor multer
Product multer
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for multer multer

Be the first to know when new high vulnerabilities affecting multer multer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

multer / multer
0 < 2.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/expressjs/multer/security/advisories/GHSA-535w-7cp7-47q4 cna.openjsf.org: https://cna.openjsf.org/security-advisories.html

Credits

๐Ÿ” O4FDev UlisesGascon arpitjain099