### Impact Multer is vulnerable to a Denial of Service (DoS) via deeply nested field names in multipart form data. The `append-field` dependency parses bracket notation in field names (e.g., `a[b][c]`) with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this. ### Patches Users should upgrade to `2.2.0` and configure `limits.fieldNestingDepth` to the minimum depth their application requires. ### Workarounds Set `limits.fields` to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.
### Impact Multer is vulnerable to a Denial of Service (DoS) via deeply nested field names in multipart form data. The `append-field` dependency parses bracket notation in field names (e.g., `a[b][c]`) with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this. ### Patches Users should upgrade to `2.2.0` and configure `limits.fieldNestingDepth` to the minimum depth their application requires. ### Workarounds Set `limits.fields` to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.
### Impact Multer is vulnerable to a Denial of Service (DoS) via deeply nested field names in multipart form data. The `append-field` dependency parses bracket notation in field names (e.g., `a[b][c]`) with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this. ### Patches Users should upgrade to `2.2.0` and configure `limits.fieldNestingDepth` to the minimum depth their application requires. ### Workarounds Set `limits.fields` to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.
### Impact Multer is vulnerable to a Denial of Service (DoS) via deeply nested field names in multipart form data. The `append-field` dependency parses bracket notation in field names (e.g., `a[b][c]`) with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this. ### Patches Users should upgrade to `2.2.0` and configure `limits.fieldNestingDepth` to the minimum depth their application requires. ### Workarounds Set `limits.fields` to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.
Update multer to 2.2.0; multer to 3.0.0-alpha.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMulter vulnerable to Denial of Service via deeply nested field names affects multer (npm), multer (npm). Severity is high. ### Impact Multer is vulnerable to a Denial of Service (DoS) via deeply nested field names in multipart form data. The `append-field` dependency parses bracket notation in field names (e.g., `a[b][c]`) with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this. ### Patches Users should upgrade to `2.2.0` and configure `limits.fieldNestingDepth` to the minimum depth their application requires. ### Workarounds Set `limits.fields` to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.
AI coding agents often install or upgrade packages automatically in npm. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| multernpm | >=1.0.0,<2.2.0 | 2.2.0 |
| multernpm | >=3.0.0-alpha.1,<3.0.0-alpha.2 | 3.0.0-alpha.2 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate multer to 2.2.0; multer to 3.0.0-alpha.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMulter vulnerable to Denial of Service via deeply nested field names affects multer (npm), multer (npm). Severity is high. ### Impact Multer is vulnerable to a Denial of Service (DoS) via deeply nested field names in multipart form data. The `append-field` dependency parses bracket notation in field names (e.g., `a[b][c]`) with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this. ### Patches Users should upgrade to `2.2.0` and configure `limits.fieldNestingDepth` to the minimum depth their application requires. ### Workarounds Set `limits.fields` to a reasonable value to reduce the number of fields an attacker can send per request. This does not fully mitigate the issue but limits the impact.
AI coding agents often install or upgrade packages automatically in npm. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| multernpm | >=1.0.0,<2.2.0 | 2.2.0 |
| multernpm | >=3.0.0-alpha.1,<3.0.0-alpha.2 | 3.0.0-alpha.2 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard