{"schema_version":1,"title":"OpenJS Foundation Multer vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in OpenJS Foundation Multer: 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88932, was published on 14 September 2026.","url":"https://junglewise.ai/threats/technologies/multer","json_url":"https://junglewise.ai/threats/technologies/multer.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/multer","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":14,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":5,"last_90_days":5,"last_365_days":10},"latest":[{"cve":"CVE-2026-88932","cvss":5.3,"epss":0.0053,"slug":"cve-2026-88932-express-multer-denial-of-service-via-orphaned-disk-writes","title":"Express multer Denial of Service via orphaned disk writes","severity":"medium","exploited":false,"published_at":"2026-09-14T09:17:01.63+00:00","url":"https://junglewise.ai/threats/cve-2026-88932-express-multer-denial-of-service-via-orphaned-disk-writes"},{"cve":"CVE-2026-82333","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82333-multer-denial-of-service-via-oversized-array-index-in-field-names","title":"multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names ca","severity":"high","exploited":false,"published_at":"2026-08-28T22:16:57.037+00:00","url":"https://junglewise.ai/threats/cve-2026-82333-multer-denial-of-service-via-oversized-array-index-in-field-names"},{"cve":"CVE-2026-77078","cvss":7.5,"epss":0.0049,"slug":"cve-2026-77078-multer-denial-of-service-via-crafted-multipart-field-names","title":"multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field na","severity":"high","exploited":false,"published_at":"2026-08-28T22:16:53.883+00:00","url":"https://junglewise.ai/threats/cve-2026-77078-multer-denial-of-service-via-crafted-multipart-field-names"},{"cve":"CVE-2026-77063","cvss":3.7,"epss":0.0023,"slug":"cve-2026-77063-multer-file-size-limit-bypass-via-async-filefilter-race-condition","title":"multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fi","severity":"low","exploited":false,"published_at":"2026-08-28T22:16:53.76+00:00","url":"https://junglewise.ai/threats/cve-2026-77063-multer-file-size-limit-bypass-via-async-filefilter-race-condition"},{"cve":"CVE-2026-77037","cvss":7.5,"epss":0.0058,"slug":"cve-2026-77037-express-multer-file-descriptor-leak-on-aborted-uploads","title":"multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated befo","severity":"high","exploited":false,"published_at":"2026-08-28T22:16:53.627+00:00","url":"https://junglewise.ai/threats/cve-2026-77037-express-multer-file-descriptor-leak-on-aborted-uploads"},{"cve":"CVE-2026-5038","cvss":5.3,"epss":0.0049,"slug":"cve-2026-5038-multer-denial-of-service-via-incomplete-cleanup-in-diskstorage","title":"Multer Denial of Service via incomplete cleanup in diskStorage","severity":"medium","exploited":false,"published_at":"2026-06-15T16:16:34.423+00:00","url":"https://junglewise.ai/threats/cve-2026-5038-multer-denial-of-service-via-incomplete-cleanup-in-diskstorage"},{"cve":"CVE-2026-5079","cvss":7.5,"epss":0.0049,"slug":"cve-2026-5079-openjs-multer-denial-of-service-via-deeply-nested-field-names","title":"OpenJS Multer Denial of Service via deeply nested field names","severity":"high","exploited":false,"published_at":"2026-06-15T14:16:37.293+00:00","url":"https://junglewise.ai/threats/cve-2026-5079-openjs-multer-denial-of-service-via-deeply-nested-field-names"},{"cve":"CVE-2026-3520","cvss":7.5,"epss":0.0094,"slug":"cve-2026-3520-expressjs-multer-denial-of-service-via-uncontrolled-recursion","title":"expressjs Multer denial of service via uncontrolled recursion","severity":"high","exploited":false,"published_at":"2026-03-04T17:16:22.61+00:00","url":"https://junglewise.ai/threats/cve-2026-3520-expressjs-multer-denial-of-service-via-uncontrolled-recursion"},{"cve":"CVE-2026-3304","cvss":7.5,"epss":0.0083,"slug":"cve-2026-3304-expressjs-multer-denial-of-service-via-incomplete-cleanup","title":"expressjs Multer denial of service via incomplete cleanup","severity":"high","exploited":false,"published_at":"2026-02-27T16:16:26.38+00:00","url":"https://junglewise.ai/threats/cve-2026-3304-expressjs-multer-denial-of-service-via-incomplete-cleanup"},{"cve":"CVE-2026-2359","cvss":7.5,"epss":0.0066,"slug":"cve-2026-2359-expressjs-multer-denial-of-service-via-resource-exhaustion","title":"expressjs multer denial of service via resource exhaustion","severity":"high","exploited":false,"published_at":"2026-02-27T16:16:25.467+00:00","url":"https://junglewise.ai/threats/cve-2026-2359-expressjs-multer-denial-of-service-via-resource-exhaustion"},{"cve":"CVE-2025-7338","cvss":3.1,"epss":0.0071,"slug":"cve-2025-7338-multer-denial-of-service-via-unhandled-exception","title":"Multer denial of service via unhandled exception","severity":"low","exploited":false,"published_at":"2025-07-17T21:01:54+00:00","url":"https://junglewise.ai/threats/cve-2025-7338-multer-denial-of-service-via-unhandled-exception"},{"cve":"CVE-2025-48997","cvss":4,"epss":0.0044,"slug":"cve-2025-48997-multer-denial-of-service-via-unhandled-exception","title":"Multer Denial of Service via unhandled exception","severity":"medium","exploited":false,"published_at":"2025-06-05T01:09:35+00:00","url":"https://junglewise.ai/threats/cve-2025-48997-multer-denial-of-service-via-unhandled-exception"},{"cve":"CVE-2025-47944","cvss":3.1,"epss":0.0081,"slug":"cve-2025-47944-multer-denial-of-service-from-malformed-multipart-requests","title":"Multer denial of service from malformed multipart requests","severity":"low","exploited":false,"published_at":"2025-05-19T22:16:30+00:00","url":"https://junglewise.ai/threats/cve-2025-47944-multer-denial-of-service-from-malformed-multipart-requests"},{"cve":"CVE-2025-47935","cvss":3.1,"epss":0.0079,"slug":"cve-2025-47935-multer-memory-leak-denial-of-service-via-unclosed-streams","title":"Multer memory leak denial of service via unclosed streams","severity":"low","exploited":false,"published_at":"2025-05-19T22:04:17+00:00","url":"https://junglewise.ai/threats/cve-2025-47935-multer-memory-leak-denial-of-service-via-unclosed-streams"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"OpenJS Foundation Morgan","slug":"morgan","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/morgan"},{"name":"OpenJS Foundation Body-Parser","slug":"body-parser","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/body-parser"}],"technology":{"hub":true,"name":"OpenJS Foundation Multer","slug":"multer","vendor":{"name":"OpenJS Foundation","slug":"openjs-foundation","url":"https://junglewise.ai/threats/vendors/openjs-foundation"},"aliases":[],"category":"library","homepage":"https://github.com/expressjs/multer","repo_url":"https://github.com/expressjs/multer","description":"A middleware for Node.js used for handling multipart/form-data, primarily used for uploading files.","url":"https://junglewise.ai/threats/technologies/multer"},"most_severe":[{"cve":"CVE-2026-3520","cvss":7.5,"epss":0.0094,"slug":"cve-2026-3520-expressjs-multer-denial-of-service-via-uncontrolled-recursion","title":"expressjs Multer denial of service via uncontrolled recursion","severity":"high","exploited":false,"published_at":"2026-03-04T17:16:22.61+00:00","url":"https://junglewise.ai/threats/cve-2026-3520-expressjs-multer-denial-of-service-via-uncontrolled-recursion"},{"cve":"CVE-2026-3304","cvss":7.5,"epss":0.0083,"slug":"cve-2026-3304-expressjs-multer-denial-of-service-via-incomplete-cleanup","title":"expressjs Multer denial of service via incomplete cleanup","severity":"high","exploited":false,"published_at":"2026-02-27T16:16:26.38+00:00","url":"https://junglewise.ai/threats/cve-2026-3304-expressjs-multer-denial-of-service-via-incomplete-cleanup"},{"cve":"CVE-2026-2359","cvss":7.5,"epss":0.0066,"slug":"cve-2026-2359-expressjs-multer-denial-of-service-via-resource-exhaustion","title":"expressjs multer denial of service via resource exhaustion","severity":"high","exploited":false,"published_at":"2026-02-27T16:16:25.467+00:00","url":"https://junglewise.ai/threats/cve-2026-2359-expressjs-multer-denial-of-service-via-resource-exhaustion"},{"cve":"CVE-2026-77037","cvss":7.5,"epss":0.0058,"slug":"cve-2026-77037-express-multer-file-descriptor-leak-on-aborted-uploads","title":"multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated befo","severity":"high","exploited":false,"published_at":"2026-08-28T22:16:53.627+00:00","url":"https://junglewise.ai/threats/cve-2026-77037-express-multer-file-descriptor-leak-on-aborted-uploads"},{"cve":"CVE-2026-82333","cvss":7.5,"epss":0.0049,"slug":"cve-2026-82333-multer-denial-of-service-via-oversized-array-index-in-field-names","title":"multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names ca","severity":"high","exploited":false,"published_at":"2026-08-28T22:16:57.037+00:00","url":"https://junglewise.ai/threats/cve-2026-82333-multer-denial-of-service-via-oversized-array-index-in-field-names"},{"cve":"CVE-2026-77078","cvss":7.5,"epss":0.0049,"slug":"cve-2026-77078-multer-denial-of-service-via-crafted-multipart-field-names","title":"multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field na","severity":"high","exploited":false,"published_at":"2026-08-28T22:16:53.883+00:00","url":"https://junglewise.ai/threats/cve-2026-77078-multer-denial-of-service-via-crafted-multipart-field-names"},{"cve":"CVE-2026-5079","cvss":7.5,"epss":0.0049,"slug":"cve-2026-5079-openjs-multer-denial-of-service-via-deeply-nested-field-names","title":"OpenJS Multer Denial of Service via deeply nested field names","severity":"high","exploited":false,"published_at":"2026-06-15T14:16:37.293+00:00","url":"https://junglewise.ai/threats/cve-2026-5079-openjs-multer-denial-of-service-via-deeply-nested-field-names"},{"cve":"CVE-2026-88932","cvss":5.3,"epss":0.0053,"slug":"cve-2026-88932-express-multer-denial-of-service-via-orphaned-disk-writes","title":"Express multer Denial of Service via orphaned disk writes","severity":"medium","exploited":false,"published_at":"2026-09-14T09:17:01.63+00:00","url":"https://junglewise.ai/threats/cve-2026-88932-express-multer-denial-of-service-via-orphaned-disk-writes"},{"cve":"CVE-2026-5038","cvss":5.3,"epss":0.0049,"slug":"cve-2026-5038-multer-denial-of-service-via-incomplete-cleanup-in-diskstorage","title":"Multer Denial of Service via incomplete cleanup in diskStorage","severity":"medium","exploited":false,"published_at":"2026-06-15T16:16:34.423+00:00","url":"https://junglewise.ai/threats/cve-2026-5038-multer-denial-of-service-via-incomplete-cleanup-in-diskstorage"},{"cve":"CVE-2025-48997","cvss":4,"epss":0.0044,"slug":"cve-2025-48997-multer-denial-of-service-via-unhandled-exception","title":"Multer Denial of Service via unhandled exception","severity":"medium","exploited":false,"published_at":"2025-06-05T01:09:35+00:00","url":"https://junglewise.ai/threats/cve-2025-48997-multer-denial-of-service-via-unhandled-exception"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}