Bug 2525796 (CVE-2026-77063) - CVE-2026-77063 multer: Multer: File size limit bypass via asynchronous file filter race condition
Summary: CVE-2026-77063 multer: Multer: File size limit bypass via asynchronous file f...
Keywords:
Status: NEW
Alias: CVE-2026-77063
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2542096 2542098 2542101 2542103 2542104 2542105 2542097 2542099 2542102
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-28 22:02 UTC by OSIDB Bzimport
Modified: 2026-09-27 14:33 UTC (History)
34 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-28 22:02:45 UTC
multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in multer's file stream handling can allow a file that exceeds the configured size limit to bypass the size-limit rejection. All versions before 2.3.0 are affected. The impact is limited because the underlying multipart parser still truncates the stream at the size limit, so this is a bypass of the limit rejection rather than uncontrolled resource consumption. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate.


Note You need to log in before you can comment on or make changes to this bug.