PT-2025-22069 · Multer · Multer

Max-Mathieu

·

Published

2025-05-19

·

Updated

2025-12-16

·

CVE-2025-47944

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Multer versions 1.4.4-lts.1 through 1.4.4-lts.x and versions prior to 2.0.0
Description: A Denial of Service (DoS) issue is present, allowing an attacker to trigger a crash of the process by sending a malformed multi-part upload request, causing an unhandled exception. This issue affects the handling of multipart/form-data.
Recommendations: For versions 1.4.4-lts.1 through 1.4.4-lts.x and versions prior to 2.0.0, upgrade to version 2.0.0 to receive a patch. At the moment, there is no information about other workarounds for this issue.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-47944
GHSA-4PG4-QVPC-4Q3H

Affected Products

Multer