Skip to content

chore: update dependency multer to ^2.1.1 [security] - #11468

Merged
dhmlau merged 1 commit into
masterfrom
renovate/npm-multer-vulnerability
Mar 10, 2026
Merged

chore: update dependency multer to ^2.1.1 [security]#11468
dhmlau merged 1 commit into
masterfrom
renovate/npm-multer-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Mar 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
multer ^2.0.2^2.1.1 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2026-3520

Impact

A vulnerability in Multer versions < 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow.

Patches

Users should upgrade to 2.1.1

Workarounds

None

Resources

CVE-2026-3304

Impact

A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion.

Patches

Users should upgrade to 2.1.0

Workarounds

None

CVE-2026-2359

Impact

A vulnerability in Multer versions < 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing resource exhaustion.

Patches

Users should upgrade to 2.1.0

Workarounds

None


Release Notes

expressjs/multer (multer)

v2.1.1

Compare Source

v2.1.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from raymondfeng as a code owner March 6, 2026 09:09
@renovate renovate Bot added dependencies Pull requests that update a dependency file SECURITY labels Mar 6, 2026
@renovate renovate Bot changed the title chore: update dependency multer to ^2.1.0 [security] chore: update dependency multer to ^2.1.0 [security] - autoclosed Mar 6, 2026
@renovate renovate Bot closed this Mar 6, 2026
@renovate
renovate Bot deleted the renovate/npm-multer-vulnerability branch March 6, 2026 13:14
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate Bot changed the title chore: update dependency multer to ^2.1.0 [security] - autoclosed chore: update dependency multer to ^2.1.1 [security] Mar 10, 2026
@renovate renovate Bot reopened this Mar 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-multer-vulnerability branch 2 times, most recently from 635297f to ca4d4d9 Compare March 10, 2026 16:45
@dhmlau
dhmlau merged commit 73c5b95 into master Mar 10, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file SECURITY

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant