CyberRota Analysis
AI-GeneratedMulter, a middleware for handling multipart/form-data in Node.js, is vulnerable to a race condition that allows files exceeding the configured size limit to bypass rejection when using an asynchronous fileFilter. While the underlying parser still truncates the stream, this issue could lead to unexpected behavior in applications that rely on strict file size enforcement. Developers using versions prior to 2.3.0 should prioritize upgrading to mitigate this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in multer's file stream handling can allow a file that exceeds the configured size limit to bypass the size-limit rejection. All versions before 2.3.0 are affected. The impact is limited because the underlying multipart parser still truncates the stream at the size limit, so this is a bypass of the limit rejection rather than uncontrolled resource consumption. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate.
Related CVEs
Other vulnerabilities affecting the same vendor(s)