Sign in

Ulises Gascón

@ulisesgascon.com
670 followers 271 following 387 posts

#OpenSource Maintainer (@nodejs.org, @expressjs.bsky.social, Lodash, Yeoman...), #TC39 Delegate and #Maker | He/Him

PostsRepliesMedia
Ulises Gascón @ulisesgascon.com · 17/09/2026
🚨 Medium-severity security fix in @fastify/static@10.1.4 just released! Patches CVE-2026-90982: @fastify/static vulnerable to route guard bypass via path case-folding github.com/fastify/fast...
github.com
@fastify/static vulnerable to route guard bypass via path case-folding
### Impact `@fastify/static` permits a route-guard or `allowedPath` bypass when the letter case of a path segment is altered, on a case-insensitive filesystem (Windows and the default macOS volume...
010
Ulises Gascón @ulisesgascon.com · 16/09/2026
🚨 Critical-severity security fix in @fastify/proxy-addr@5.1.1 just released! Patches CVE-2026-92395: @fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet github.com/fastify/prox...
github.com
@fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
### Impact `@fastify/proxy-addr` determines which network hops are trusted proxies so that `X-Forwarded-For` can be believed. This fork of `proxy-addr` inherited the same logic as the vulnerable u...
010
Ulises Gascón @ulisesgascon.com · 16/09/2026
🚨 High-severity security fix in @fastify/auth@5.1.1 just released! Patches CVE-2026-92087: @fastify/auth vulnerable to Authorization Bypass via order-dependent evaluation of composed auth github.com/fastify/fast...
github.com
@fastify/auth vulnerable to Authorization Bypass via order-dependent evaluation of composed auth
### Impact `@fastify/auth` composes multiple authentication functions with AND/OR relations, including nested arrays (for example `fastify.auth([f1, [f2, f3]], { relation: 'or' })` meaning `f1 OR ...
010
Ulises Gascón @ulisesgascon.com · 16/09/2026
🚨 Medium-severity security fix in fastify@5.12.5 just released! Patches CVE-2026-92081: fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses github.com/fastify/fast...
github.com
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
### Impact `fastify` crashes with an uncaught `ERR_HTTP2_INVALID_CONNECTION_HEADERS` exception when a route that registers a response trailer via `reply.trailer()` is served over HTTP/2. Fastify...
010
Ulises Gascón @ulisesgascon.com · 15/09/2026
🚨 Medium-severity security fix in fast-uri@4.1.5 just released! Patches CVE-2026-86818: fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization github.com/fastify/fast...
github.com
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
### Impact `fast-uri`'s `mailto` scheme parser compares each query field name to the reserved names (`to`, `subject`, `body`) while the name is still percent-encoded, and only percent-decodes it...
010
Ulises Gascón @ulisesgascon.com · 15/09/2026
🚨 Medium-severity security fix in fast-uri 4.1.5, 3.1.8, and 2.4.7 just released! Patches CVE-2026-86472: fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets github.com/fastify/fast...
github.com
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
### Impact `fast-uri` folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase unreserved octet such as `%41` decodes to a literal `A` that is never folded. F...
010
Ulises Gascón @ulisesgascon.com · 15/09/2026
🚀 Just released proxy-addr@2.0.8 📦️️️️️️️️️ 🍿 #release details: github.com/jshttp/proxy...
github.com
Release 2.0.8 · jshttp/proxy-addr
Important Fix CVE-2026-90711 (GHSA-jqcg-44mw-7w3h) What's Changed Add OSSF scorecard action by @carpasse in #27 Fix ci pipeline and add missing Node.JS versions by @carpasse in #26 [StepSecurity...
010
Ulises Gascón @ulisesgascon.com · 15/09/2026
🚨 Critical-severity security fix in proxy-addr@2.0.8 just released! Patches CVE-2026-90711: proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet github.com/jshttp/proxy...
github.com
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
### Impact `proxy-addr` determines which network hops are trusted proxies so that `X-Forwarded-For` can be believed. When an application configures a trust subnet as an IPv4-mapped IPv6 address ...
020
Ulises Gascón @ulisesgascon.com · 15/09/2026
🚨 Medium-severity security fix in moment@2.31.0 just released! Patches CVE-2026-17495: moment vulnerable to Path Traversal via crafted non-string locale name github.com/moment/momen...
github.com
moment vulnerable to Path Traversal via crafted non-string locale name
### Impact moment before 2.31.0 is vulnerable to path traversal in `moment.locale()`. When an application passes a non-string, attacker-influenced value to `moment.locale()`, a specially crafted...
031
Ulises Gascón @ulisesgascon.com · 14/09/2026
🚨 Medium-severity security fix in multer@2.4.0 just released! Patches CVE-2026-88932: multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads github.com/expressjs/mu...
github.com
multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
### Impact Multer's `diskStorage` can leave complete, orphaned files on disk when a multipart upload is aborted in the brief window before the storage engine assigns the file path. This is an in...
010
Ulises Gascón @ulisesgascon.com · 14/09/2026
🎉 multer@2.4.0 finally supports Google Cloud Functions and Firebase with the new streamHandler option
JavaScript code creating a multer instance with the new streamHandler option. The handler checks if req.rawBody exists, as on Google Cloud Functions and Firebase, and feeds it to busboy with busboy.end(req.rawBody); otherwise it falls back to req.pipe(busboy). Below, an Express route uses upload.single to accept a file and respond with its name and size.
012
Ulises Gascón @ulisesgascon.com · 14/09/2026
multer@2.4.0 is out 🎉 🔒 Security fix (CVE-2026-88932) ☁️ Google Cloud Functions / Firebase supported via the new streamHandler option 📏 Per-request limits: pass a function 🧾 err.filename tells you which file broke the size limit ⚡ Misconfigured limits now fail at startup github.com/expressjs/mu...
github.com
Release v2.4.0 · expressjs/multer
Highlights multer finally supports Google Cloud Functions and Firebase 🎉 These platforms read the request body before your code runs, so multer's classic req.pipe(busboy) received nothing: empty re...
010
Ulises Gascón @ulisesgascon.com · 14/09/2026
🚀 Just released express@4.22.3 📦️️️️️️️️ 🍿 #release details: github.com/expressjs/ex...
github.com
Release v4.22.3 · expressjs/express
What's Changed Update path-to-regexp to 0.1.13 to fix CVE-2026-4867 by @baryman in #7135 feat: allow conditional revalidation for QUERY requests (v4) by @Cherry in #7377 deps: qs@~6.16.0 by @lazer...
040
Ulises Gascón @ulisesgascon.com · 12/09/2026
🫶 As part of the @openjsf.org #CNA, we also want to encourage #maintainers, in our projects and beyond, to give themselves permission to take a break. #Burnout is real for #maintainers, especially in #security work. openjsf.org/blog/the-ope...
openjsf.org
The OpenJS Foundation CNA is taking a coordinated break: September 17 to October 6, 2026 | OpenJS Foundation
To combat volunteer burnout driven by a surge in AI-generated vulnerability reports, the OpenJS Foundation CNA will temporarily pause all security operations from September 17 to October 6, 2026. This...
031
Ulises Gascón @ulisesgascon.com · 11/09/2026
🚨 High-severity security fix in compression@1.8.2 just released! Patches CVE-2026-87776: compression vulnerable to Denial of Service via memory leak on premature response close github.com/expressjs/co...
github.com
compression vulnerable to Denial of Service via memory leak on premature response close
### Impact A vulnerability in compression `< 1.8.2` allows an attacker to trigger a Denial of Service (DoS) by disconnecting while a compressed response is being sent. When the client aborts the...
021
Ulises Gascón @ulisesgascon.com · 11/09/2026
🚀 Just released compression@1.8.2 📦️️️️️️️ 🍿 #release details: github.com/expressjs/co...
github.com
Release v1.8.2 · expressjs/compression
Important Fix CVE-2026-87776 (GHSA-vc2v-76pw-4v95) What's Changed chore: add funding to package.json by @bjohansebas in #248 build(deps): bump github/codeql-action from 3.29.2 to 3.29.5 by @depe...
020
Ulises Gascón @ulisesgascon.com · 11/09/2026
🚨 Medium-severity security fix in hbs@4.3.1 just released! Patches CVE-2026-87123: hbs vulnerable to Denial of Service via unhandled exception in async helper output escaping github.com/pillarjs/hbs...
github.com
hbs vulnerable to Denial of Service via unhandled exception in async helper output escaping
### Impact hbs 4.3.0 can crash the Node.js process when an async helper (registered with `registerAsyncHelper`) resolves to an object whose `toHTML` property is truthy but not callable. During out...
010
Ulises Gascón @ulisesgascon.com · 11/09/2026
🚀 Just released hbs@4.3.1 📦️️️️️️ 🍿 #release details: github.com/pillarjs/hbs...
github.com
Release 4.3.1 · pillarjs/hbs
Important Fix CVE-2026-87123 (GHSA-3c55-w9jx-p5jr) What's Changed fix: treat async substitution throws as render errors by @official-burak in #276 4.3.1 by @UlisesGascon in #277 New Contributor...
010
Ulises Gascón @ulisesgascon.com · 11/09/2026
🚨 Medium-severity security fix in morgan@1.12.1 just released! Patches CVE-2026-87859: morgan vulnerable to Log Injection via unescaped double quote in quoted log fields github.com/expressjs/mo...
github.com
morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
### Impact morgan writes attacker-controlled request data into the access log. The escaping added in 1.11.0 and 1.12.0 neutralizes control characters, the Unicode line separators and the backslash...
010
Ulises Gascón @ulisesgascon.com · 11/09/2026
🚀 Just released morgan@1.12.1 📦️️️️️ 🍿 #release details: github.com/expressjs/mo...
github.com
Release 1.12.1 · expressjs/morgan
Important Security fix for CVE-2026-87859 (GHSA-9f6g-j8ch-79g4) What's Changed docs: fix typos across documentation by @vaibhavmashal in #378 test: run CI on Windows and macOS by @kilisamemarisa...
010
Ulises Gascón @ulisesgascon.com · 11/09/2026
🚨 High-severity security fix in multiparty@4.3.1 just released! Patches CVE-2026-87908: multiparty vulnerable to Denial of Service via unbounded part-header accumulation github.com/pillarjs/mul...
github.com
multiparty vulnerable to Denial of Service via unbounded part-header accumulation
### Impact multiparty@4.3.0 and lower versions are vulnerable to denial of service via uncontrolled memory allocation. multiparty bounds accumulated field values (`maxFieldsSize`) and file bytes (...
011
Ulises Gascón @ulisesgascon.com · 10/09/2026
🚨 Medium-severity security fix in cookies@0.9.2 just released! Patches CVE-2026-88038: cookies vulnerable to Set-Cookie attribute injection via unvalidated domain and path options github.com/pillarjs/coo...
github.com
cookies vulnerable to Set-Cookie attribute injection via unvalidated domain and path options
### Impact `cookies` validates cookie name and value against character sets that reject `;`, but the `domain` and `path` options are checked only against a permissive RFC 7230 field-content matche...
010
Ulises Gascón @ulisesgascon.com · 09/09/2026
🔐 Does your project have a threat model? It tells reporters what counts as a vulnerability before they spend hours on it, and saves you from triaging the same invalid findings again. Moment just added one, and it is a great starting point to copy from 🥳 github.com/moment/momen...
github.com
[misc] Add security threat model by UlisesGascon · Pull Request #6445 · moment/moment
Adds a docs/threat-model.md defining what is and is not a security vulnerability in Moment, and links it from SECURITY.md and the README Resources list. Modeled on the threat models of sibling Open...
010
Ulises Gascón @ulisesgascon.com · 08/09/2026
🚨 High-severity security fix in fastify-cli@8.0.1 just released! Patches CVE-2026-75021: fastify-cli vulnerable to remote code execution via ignored explicit Inspector bind address github.com/fastify/fast...
github.com
fastify-cli vulnerable to remote code execution via ignored explicit Inspector bind address
### Impact `fastify-cli` versions from 1.5.0 through 8.0.0 select the Node Inspector host with an incorrectly grouped conditional expression. Because logical OR binds tighter than the ternary oper...
000
Ulises Gascón @ulisesgascon.com · 08/09/2026
🚀 Just released body-parser@1.20.8 📦️️️️ 🍿 #release details: github.com/expressjs/bo...
github.com
Release 1.20.8 · expressjs/body-parser
Important Same code base as 1.20.7. This was created to test the new release process. What's Changed ci: backport npm-publish workflow from master by @UlisesGascon in #769 1.20.8 by @UlisesGascon ...
000
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 Moderate-severity security fix in undici (7.29.1, 8.10.2) just released! Patches CVE-2026-18149: undici vulnerable to Denial of Service via orphaned RetryHandler response body github.com/nodejs/undic...
github.com
undici vulnerable to Denial of Service via orphaned RetryHandler response body
### Impact undici's `RetryHandler` can leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the original `response.body` held...
020
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 Low-severity security fix in undici (6.28.1, 7.29.1, 8.10.2) just released! Patches CVE-2026-18540: undici vulnerable to downstream response splitting via retry interceptor github.com/nodejs/undic...
github.com
undici vulnerable to downstream response splitting via retry interceptor
### Impact Undici's `interceptors.retry()` can resume a request after a partial response and append the resumed bytes to an already partially delivered body, while the application still receives t...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 High-severity security fix in undici (6.28.1, 7.29.1, 8.10.2) just released! Patches CVE-2026-19534: undici vulnerable to Denial of Service via unrequested WebSocket subprotocol github.com/nodejs/undic...
github.com
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
### Impact The undici WebSocket client throws an uncaught `TypeError` during the opening handshake when a server's `101` response includes a `Sec-WebSocket-Protocol` header that the client never r...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 Moderate-severity security fix in undici (7.29.1, 8.10.2) just released! Patches CVE-2026-84890: undici vulnerable to Denial of Service via unbounded decompression of compressed responses github.com/nodejs/undic...
github.com
undici vulnerable to Denial of Service via unbounded decompression of compressed responses
### Impact The `interceptors.decompress()` interceptor decompresses HTTP response bodies according to the untrusted `Content-Encoding` header. The number of decompression layers is capped at 5, bu...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 Moderate-severity security fix in undici (7.29.1, 8.10.2) just released! Patches CVE-2026-84933: undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches github.com/nodejs/undic...
github.com
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
### Impact undici's `interceptors.cache()` does not handle `Set-Cookie` in the cache path. In shared-cache mode (`type: 'shared'`, the default), a cacheable response (for example `Cache-Control: p...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 Low-severity security fix in undici (7.29.1, 8.10.2) just released! Patches CVE-2026-84947: undici vulnerable to response truncation via oversized chunked responses in the dump interceptor github.com/nodejs/undic...
github.com
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
### Impact undici's `interceptors.dump()` reads and discards response bodies up to a configurable `maxSize`. When a response declares a `Content-Length` that exceeds `maxSize`, the request is abor...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 High-severity security fix in undici (7.29.1, 8.10.2) just released! Patches CVE-2026-84961: undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool github.com/nodejs/undic...
github.com
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
### Impact undici's `BalancedPool` passes its constructor options through a JSON-based deep clone (`JSON.parse(JSON.stringify(...))`) before forwarding them to each per-upstream `Pool`. JSON canno...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 Low-severity security fix in undici (7.29.1, 8.10.2) just released! Patches CVE-2026-85008: undici vulnerable to caching and replay of unsafe HTTP method responses github.com/nodejs/undic...
github.com
undici vulnerable to caching and replay of unsafe HTTP method responses
### Impact undici's `interceptors.cache()` documents that it caches only safe HTTP methods. However, its internal skip-list is built by subtracting the configured methods from the safe-methods set...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 High-severity security fix in undici@8.10.2 just released! Patches CVE-2026-85152: undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors github.com/nodejs/undic...
github.com
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
## Impact When `interceptors.cache()` or `interceptors.deduplicate()` is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its own `origin`, undi...
110
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 Moderate-severity security fix in undici (7.29.1, 8.10.2) just released! Patches CVE-2026-85014: undici vulnerable to Denial of Service via WebSocketStream unclean close github.com/nodejs/undic...
github.com
undici vulnerable to Denial of Service via WebSocketStream unclean close
## Impact undici's `WebSocketStream` crashes the client process when a WebSocket connection is closed abruptly without a close handshake. On such an unclean close, the internal socket-close handle...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 Moderate-severity security fix in undici (6.28.1, 7.29.1, 8.10.2) just released! Patches CVE-2026-85024: undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression github.com/nodejs/undic...
github.com
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
## Impact undici's WebSocket client (including Node.js's bundled `globalThis.WebSocket`) crashes the entire Node.js process when a remote WebSocket peer sends a permessage-deflate compressed messa...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 High-severity security fix in fastify@5.12.2 just released! Patches CVE-2026-84428: header validation bypass via incomplete schema case normalization. github.com/fastify/fast...
github.com
fastify vulnerable to header validation bypass via incomplete schema case normalization
### Impact Fastify lowercases header-schema property names before compiling the schema, because Node.js stores request header names in lowercase. That normalization was incomplete: it lowercased o...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 High-severity security fix in fastify@5.12.2 just released! Patches CVE-2026-84469: request validation bypass via skipped boolean false schemas. github.com/fastify/fast...
github.com
fastify vulnerable to request validation bypass via skipped boolean false schemas
### Impact Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean `false` as a valid schema that rejects every...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 High-severity security fix in fastify@5.12.2 just released! Patches CVE-2026-76169: authentication bypass via malformed URLs reaching encapsulated not-found handlers. github.com/fastify/fast...
github.com
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
### Impact Fastify routes a malformed URL under one plugin prefix to the custom not-found handler of a different sibling plugin, invoking the handler registered last and skipping the `preHandler` ...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 High-severity security fix in fastify@5.12.2 just released! Patches CVE-2026-84504: request body replacement via an async validation result collision. github.com/fastify/fast...
github.com
fastify vulnerable to request body replacement via an async validation result collision
### Impact Fastify runs a route's validator and, for a result shaped like `{ value, error }`, unwraps it: an `error` becomes a validation failure and `value` replaces the request part. This conven...
010
Ulises Gascón @ulisesgascon.com · 04/09/2026
🚨 Critical-severity security fix in @fastify/middie@9.3.4 just released! Patches CVE-2026-85184: path-scoped middleware bypass via absolute-form request target. github.com/fastify/midd...
github.com
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
### Impact `@fastify/middie` versions `>= 9.1.0, <= 9.3.3` match path-scoped middleware against the raw request target, while Fastify's router (find-my-way) resolves an absolute-form target to its...
010
Ulises Gascón @ulisesgascon.com · 03/09/2026
🚨 High-severity security fix in @fastify/http-proxy@11.6.2 just released! Patches CVE-2026-85124: prefix escape via backslash dot-segments. github.com/fastify/fast...
github.com
@fastify/http-proxy vulnerable to prefix escape via backslash dot-segments
## Impact `@fastify/http-proxy` validates proxied WebSocket destinations against the `rewritePrefix` boundary, but the plain HTTP request path does not apply the same check. A path that uses backs...
010
Ulises Gascón @ulisesgascon.com · 03/09/2026
CVE-2026-76844 for webpack-dev-middleware was published by VulnCheck without coordinating with the maintainers or the OpenJS Foundation CNA, which holds CNA scope for webpack, and before any fix existed. The coordinated advisory and fix are now out github.com/webpack/webp...
github.com
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
> [!IMPORTANT] > CVE-2026-76844 was assigned and published for this issue by VulnCheck on 2026-08-24 without prior coordination with the webpack maintainers or the OpenJS Foundation, which holds t...
010
Ulises Gascón @ulisesgascon.com · 02/09/2026
🚨 High-severity security fix in fast-uri (4.1.4, 3.1.7, 2.4.6) just released! Patches CVE-2026-84394: fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority github.com/fastify/fast...
github.com
fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
### Impact `fast-uri` accepts a host that contains an unbalanced or misplaced authority bracket (`[` or `]`) without reporting an error. A host that starts with `[` but does not end with `]`, such...
010
Ulises Gascón @ulisesgascon.com · 02/09/2026
🚨 High-severity security fix in fast-uri (4.1.4, 3.1.7, 2.4.6) just released! Patches CVE-2026-84292: fast-uri vulnerable to authority injection via an unvalidated port in serialize github.com/fastify/fast...
github.com
fast-uri vulnerable to authority injection via an unvalidated port in serialize
### Impact `fast-uri` serializes the `port` component of a URI without validating it. When recomposing the authority, `fast-uri` escapes the userinfo and host components but concatenates the port ...
010
Ulises Gascón @ulisesgascon.com · 31/08/2026
🔒️️️ Security update: Check out the August 2026 #Security Releases for #Express Stay safe out there 🫡 expressjs.com/en/blog/2026...
expressjs.com
August 2026 Security Releases · Express.js
Security releases for hbs, multer, and morgan have been published. We recommend that all users upgrade as soon as possible.
020
Ulises Gascón @ulisesgascon.com · 29/08/2026
🤓 Next multer release in the oven github.com/expressjs/mu...
github.com
Release: 2.4.0 by UlisesGascon · Pull Request #1469 · expressjs/multer
Blockers We need/want to land (waiting for reviews): docs: add FormData upload examples #896 feat: expose busboy defCharset, highWaterMark and fileHwm options #1465 feat: add streamHandler opti...
010
Ulises Gascón @ulisesgascon.com · 28/08/2026
🚨 High-severity security fix in multer@2.3.0 just released! Patches CVE-2026-82333: multer vulnerable to denial of service via oversized array index in field names github.com/expressjs/mu...
github.com
multer vulnerable to Denial of Service via oversized array index in field names
### Impact multer is vulnerable to a Denial of Service (DoS) via a crafted array index in multipart field names. The `append-field` dependency parses bracket notation in field names, and a large...
010
Ulises Gascón @ulisesgascon.com · 28/08/2026
🚨 High-severity security fix in multer@2.3.0 just released! Patches CVE-2026-77078: multer vulnerable to denial of service via crafted multipart field names github.com/expressjs/mu...
github.com
multer vulnerable to Denial of Service via crafted multipart field names
### Impact A vulnerability in multer allows a remote, unauthenticated attacker to crash the Node.js process with a single `multipart/form-data` request. Two specially crafted text field names ca...
010
Ulises Gascón @ulisesgascon.com · 28/08/2026
🚨 Low-severity security fix in multer@2.3.0 just released! Patches CVE-2026-77063: multer vulnerable to file size limit bypass via async fileFilter race condition github.com/expressjs/mu...
github.com
multer vulnerable to file size limit bypass via async fileFilter race condition
### Impact When `multer` is configured with an asynchronous `fileFilter`, the `limits.fileSize` limit can be bypassed. The `'limit'` event is registered inside the async `fileFilter` callback, s...
010