Missing Release of Resource after Effective Lifetime in multer - CVE-2026-2359

 

Missing Release of Resource after Effective Lifetime in multer - CVE-2026-2359

Published: April 27, 2026


Vulnerability identifier: #VU128186
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2359
CWE-ID: CWE-772
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of resource after effective lifetime in the file upload handling component when processing a file upload connection that is dropped prematurely. A remote attacker can drop the connection during file upload to cause a denial of service.

The issue can lead to resource exhaustion.


Affected software

multer
IBM Watson Discovery for IBM Cloud Pak for Data
IBM QRadar Data Synchronization App

How to mitigate CVE-2026-2359

Install security update from vendor's website.

multer - update to 2.1.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM QRadar Data Synchronization App - update to 4.0.0

External References

Related Security Bulletins