Incomplete cleanup in multer - CVE-2026-5038
Published: June 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incomplete cleanup in diskStorage when handling aborted or malformed multipart uploads. A remote attacker can send a malformed multipart upload or abort an upload to cause a denial of service.
Exploitation causes orphaned partial files to accumulate on disk.
Affected software
IBM App Connect Enterprise
How to mitigate CVE-2026-5038
IBM App Connect Enterprise - addressed in versions 12.0.12.28, 13.0.8.0