Express.js is a lightweight Node.js web application framework whose vulnerability profile is concentrated in a narrow set of middleware and utility modules such as multer, basic-auth-connect, and method-override that handle request parsing and authentication concerns. The observed weaknesses cluster around resource management and timing-related issues including incomplete cleanup, resource leaks, and observable timing discrepancies, reflecting the asynchronous event-driven model of Node.js applications. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Expressjs over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5079HIGH Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependenc | Jun 15, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-5038HIGH Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orp | Jun 15, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-3304HIGH Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sendi | Feb 27, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-3520HIGH Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sendi | Mar 4, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-2359HIGH Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropp | Feb 27, 2026 | 7.5 | 28 | NO | NO |
CVE-2017-16136HIGH method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulne | Jun 7, 2018 | 7.5 | 21 | NO | NO |
CVE-2025-7338HIGH Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.2 allows an attacker to | Jul 17, 2025 | 7.5 | 19 | NO | NO |
CVE-2024-47178MEDIUM basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This | Sep 30, 2024 | 5.3 | 19 | NO | NO |
CVE-2024-9266MEDIUM URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3. | Oct 3, 2024 | 4.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Expressjs.
Media articles that mention a CVE ID that affects a product developed by Expressjs — matched by CVE ID, not by vendor name.