Missing Release of Resource after Effective Lifetime in multer - CVE-2026-2359
Published: April 27, 2026
multer
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of resource after effective lifetime in the file upload handling component when processing a file upload connection that is dropped prematurely. A remote attacker can drop the connection during file upload to cause a denial of service.
The issue can lead to resource exhaustion.