CVE-2026-77063

multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in multer's file stream handling can allow a file that exceeds the configured size limit to bypass the size-limit rejection. All versions before 2.3.0 are affected. The impact is limited because the underlying multipart parser still truncates the stream at the size limit, so this is a bypass of the limit rejection rather than uncontrolled resource consumption. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate.
Configurations

Configuration 1 (hide)

cpe:2.3:a:expressjs:multer:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-08-28 22:16

Updated : 2026-09-02 14:46


NVD link : CVE-2026-77063

Mitre link : CVE-2026-77063

CVE.ORG link : CVE-2026-77063


JSON object : View

Products Affected

expressjs

  • multer
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')