CVE-2025-7338
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-17

Last updated on: 2025-07-17

Assigner: openjs

Description
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.2 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed multi-part upload request. This request causes an unhandled exception, leading to a crash of the process. Users should upgrade to version 2.0.2 to receive a patch. No known workarounds are available.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-17
Last Modified
2025-07-17
Generated
2026-05-27
AI Q&A
2025-07-17
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
openjs_foundation on-headers *
expressjs multer 2.0.2
expressjs multer 1.4.4-lts.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the Multer node.js middleware for handling multipart/form-data. It allows an attacker to cause a Denial of Service (DoS) by sending a malformed multi-part upload request, which triggers an unhandled exception and crashes the process.


How can this vulnerability impact me? :

The vulnerability can impact you by causing your application or service that uses Multer to crash unexpectedly due to a Denial of Service attack, potentially leading to downtime and loss of availability.


What immediate steps should I take to mitigate this vulnerability?

The immediate step to mitigate this vulnerability is to upgrade Multer to version 2.0.2 or later, as this version contains the patch for the Denial of Service vulnerability. No known workarounds are available.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart