CVE-2026-88932: Uncontrolled Resource Consumption (Denial of Service) via orphaned disk writes on aborted uploads in multer
Vulnerability ID: CVE-2026-88932
CVSS Score: 5.3
Published: 2026-09-28
An uncontrolled resource consumption vulnerability exists in the multer middleware for Node.js (versions 2.2.0 through 2.3.0) when handling aborted multipart uploads using disk storage. Due to an asynchronous race condition in path resolution, files can become permanently orphaned on disk, leading to storage exhaustion and denial of service.
TL;DR
Unauthenticated remote attackers can exhaust server disk space and trigger a denial of service (DoS) by initiating and immediately aborting multipart file uploads before multer completes file path resolution.
Technical Details
- CWE ID: CWE-400, CWE-459
- Attack Vector: Network (AV:N)
- CVSS Score: 5.3 (Medium)
- EPSS Score: 0.00532
- Impact: Denial of Service via Disk Storage Exhaustion
- Exploit Status: No public weaponized exploits available
- CISA KEV Status: Not Listed
Affected Systems
- multer (Node.js middleware)
-
multer: >= 2.2.0, <= 2.3.0 (Fixed in:
2.4.0)
Code Analysis
Commit: 53337f9
Fix orphan file cleanup when the abort lands before the engine assigns a path
@@ -129,6 +129,8 @@ function makeMiddleware (setup) {
var isDone = false
var readFinished = false
var errorOccured = false
+ var abortCleanupDone = false
+ var abortRemovedFiles = new Set()
var pendingWrites = new Counter()
var uploadedFiles = []
var pendingFiles = []
Mitigation Strategies
- Upgrade multer to version 2.4.0 or later.
- Enforce reverse proxy timeouts (such as Nginx client_body_timeout) to drop slow or aborted uploads.
- Set up an automated system cron task to clean old, untracked files from the upload folder.
- Migrate to memoryStorage for small uploads to completely bypass filesystem storage exposure.
Remediation Steps:
- Check package.json for the 'multer' dependency in all active Node.js services.
- If the version is between 2.2.0 and 2.3.0, update the dependency reference to '^2.4.0'.
- Run 'npm install' or 'yarn install' to retrieve and apply the patched version.
- Run regression tests to verify that multipart upload operations perform correctly.
- Deploy the updated codebase to testing and production environments.
References
- GitHub Security Advisory GHSA-3pph-fpjx-jg34
- OpenJS Foundation Security Advisories
- Official Patch Commit
- Multer v2.4.0 Release Notes
Read the full report for CVE-2026-88932 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)