highCVSS 7.5Vulnerability

CVE-2026-77037

### Impact A vulnerability in multer `2.2.0` allows an attacker to trigger a Denial of Service (DoS) by aborting or truncating multipart uploads. When using `diskStorage`, the destination write stream is not closed if the upload is aborted before it finishes, so each failed request leaks an open file descriptor and retains its disk blocks until the process exits. Repeated failed uploads can exhaust the available file descriptors. All applications using multer's disk storage are affected. ### Patches Users should upgrade to `2.3.0`. ### Workarounds None.

Properties

summary
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
severity
high
cvss_score
7.5
epss_score
0.00347
ghsa_published
2026-09-08T21:29:51Z
source_url
https://github.com/advisories/GHSA-qfvm-cv95-jqjf
ghsa_updated
2026-09-08T21:29:51Z
ghsa_id
GHSA-qfvm-cv95-jqjf
score
7.5
cve_id
CVE-2026-77037
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
false
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-28T22:16:53.627
last_modified
2026-09-02T14:47:21.140
epss_percentile
0.27682

Related Entities (8)

VULNERABLE_TO (1)

[Software]npm/multer

AFFECTS (1)

[Software]npm/multer

REPORTED_BY (1)

[Source]GitHub Advisory Database

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (2)

[Weakness]Uncontrolled Resource Consumption
[Weakness]Incomplete Cleanup

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph