Multer Vulnerable to Denial of Service via Uncontrolled Recursion
Description
Published by the National Vulnerability Database
Mar 4, 2026
Published to the GitHub Advisory Database
Mar 5, 2026
Reviewed
Mar 5, 2026
Last updated
Mar 5, 2026
Impact
A vulnerability in Multer versions < 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow.
Patches
Users should upgrade to
2.1.1Workarounds
None
Resources
References