CVE-2026-3304
Impact
A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion.
Patches
Users should upgrade to 2.1.0
Workarounds
None
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/expressjs/multer/security/advisories/GHSA-xf7r-hgr6-v32p, https://nvd.nist.gov/vuln/detail/CVE-2026-3304, https://github.com/expressjs/multer/commit/739919097dde3921ec31b930e4b9025036fa74ee, https://cna.openjsf.org/security-advisories.html, https://github.com/expressjs/multer, https://www.cve.org/CVERecord?id=CVE-2026-3304
