SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-77063

LOW · CVSS 3.7 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Multer, a middleware for handling multipart/form-data in Node.js, is vulnerable to a race condition that allows files exceeding the configured size limit to bypass rejection when using an asynchronous fileFilter. While the underlying parser still truncates the stream, this issue could lead to unexpected behavior in applications that rely on strict file size enforcement. Developers using versions prior to 2.3.0 should prioritize upgrading to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77063
Severity
LOW
CVSS
3.7
EPSS
0.16%

Original NVD Description

multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in multer's file stream handling can allow a file that exceeds the configured size limit to bypass the size-limit rejection. All versions before 2.3.0 are affected. The impact is limited because the underlying multipart parser still truncates the stream at the size limit, so this is a bypass of the limit rejection rather than uncontrolled resource consumption. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate.

Related CVEs

Other vulnerabilities affecting the same vendor(s)