PT-2025-29923 · Multer · Multer

Ctcpip

·

Published

2025-07-17

·

Updated

2026-06-04

·

CVE-2025-7338

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Multer versions 1.4.4-lts.1 through 2.0.1
Description Multer is a node.js middleware for handling multipart/form-data. A vulnerability allows an attacker to trigger a Denial of Service (DoS) by sending a malformed multi-part upload request. This request causes an unhandled exception, leading to a crash of the process.
Recommendations Upgrade to version 2.0.2.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7338
GHSA-FJGF-RC76-4X9P

Affected Products

Multer