CVE-2026-3520 is a Denial of Service (DoS) vulnerability in Multer, a Node.js middleware for handling multipart/form-data, affecting versions prior to 2.1.1. An unauthenticated attacker can trigger a stack overflow by sending malformed requests, leading to a high-severity impact on availability with a CVSS score of 8.7. There are no known active exploits, public exploit code, or workarounds, though the vulnerability has garnered some community discussion and media coverage. Users are advised to upgrade to Multer version 2.1.1 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.1CPE matchmatch criteria | cpe:2.3:a:expressjs:multer:*:*:*:*:*:node.js:*:* | ||
>= 0, < 2.1.1CPE match | cpe:2.3:a:expressjs:multer:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.