CVE-2026-2359
Multer <2.1.0 - DoS
Title source: llmDescription
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.
Scores
EPSS
0.0006
EPSS Percentile
17.1%
Classification
CWE
CWE-772
Status
draft
Affected Products (1)
npm/multer
< 2.1.0npm
Timeline
Published
Feb 27, 2026
Tracked Since
Feb 27, 2026