CVE-2026-2359
Impact
A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing resource exhaustion.
Patches
Users should upgrade to 2.1.0
Workarounds
None
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/expressjs/multer/security/advisories/GHSA-v52c-386h-88mc, https://nvd.nist.gov/vuln/detail/CVE-2026-2359, https://github.com/expressjs/multer/commit/cccf0fe0e64150c4f42ccf6654165c0d66b9adab, https://cna.openjsf.org/security-advisories.html, https://github.com/expressjs/multer, https://www.cve.org/CVERecord?id=CVE-2026-2359