Multer is a node.js middleware for handling multipart/form-data. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.
The product does not properly “clean up” and remove temporary or supporting resources after they have been used.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Multer | Expressjs | * | 2.1.0 (excluding) |
| Red Hat Developer Hub 1.8 | RedHat | rhdh/rhdh-hub-rhel9:1774545605 | * |
| Red Hat Developer Hub 1.9 | RedHat | rhdh/rhdh-hub-rhel9:1775140647 | * |