CVE-2026-5038: multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
Impact
A vulnerability in Multer allows an attacker to trigger a Denial of Service (DoS) by aborting or sending malformed multipart uploads, causing orphaned partial files to accumulate on disk when using diskStorage.
Patches
Users should upgrade to 2.2.0, 3.0.0-alpha.2 or higher
Workarounds
None
Other sources
Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to the underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required.
Patches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2 (3.x prerelease). Both versions track in-flight write streams and clean them up on the abort path.
Workarounds: None.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/multerto a version that resolves this vulnerability.Fixed in 2.2.0 - Upgrade
Upgrade
npm/multerto a version that resolves this vulnerability.Fixed in 3.0.0-alpha.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5038?
CVE-2026-5038 has a medium severity rating of 5.3.
How do I fix CVE-2026-5038?
To fix CVE-2026-5038, you should update multer to version 2.1.2 or later.
What impact does CVE-2026-5038 have?
CVE-2026-5038 can lead to a Denial of Service due to orphaned partial files being left on disk.
Which versions of multer are affected by CVE-2026-5038?
CVE-2026-5038 affects multer versions from 2.0.0-alpha.1 to 2.1.1 and 3.0.0-alpha.1.
What type of vulnerability is CVE-2026-5038?
CVE-2026-5038 is a Denial of Service vulnerability related to incomplete cleanup of aborted uploads.