# CVE-2026-88932

## Summary

- **CVE ID:** CVE-2026-88932
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-400, CWE-459
- **Published:** Sep 14, 2026
- **Last Modified:** Sep 14, 2026

## Description

multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A remote unauthenticated attacker can repeatedly start and abort uploads to accumulate orphaned files and exhaust disk space, causing a denial of service. The issue is fixed in multer 2.4.0, and users should upgrade to 2.4.0 or later.

## Affected Products

- multer — multer (2.2.0)
- multer — multer (2.4.0)

## References

- [CNA](https://github.com/expressjs/multer/security/advisories/GHSA-3pph-fpjx-jg34)
- [CNA](https://cna.openjsf.org/security-advisories.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.31%
- **EPSS Percentile:** 24.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._