CVE•Published 2026-02-27•Modified 2026-07-15•0 articles on news•4 live references•NVD data
CVE-2026-3304Expressjs · Multer
Vulnerability data via NVD (ingested)
CVSS v3.1
7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS percentile
47
Exploit Prediction Scoring System · top 53% of all CVEs
Weaknesses (CWE)
Description
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.
Timeline
Published 2026-02-27
Modified 2026-07-15
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-3304Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Expressjs Multer"All exposed Expressjs Multer instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Multer"HTTP body or banner mentions "Multer" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-3304Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-3304Censys host search filtered to this CVE id.
grep.app
CVE-2026-3304Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-3304GitHub code search for direct mentions.
Google dork
"CVE-2026-3304" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (5)
CVE-2026-33045 repos
DarkFunct/TK-CVE-RepoPython
TK-CVE-Repo
Nsbx/awesome-starsunknown
My Awesome List generated by : https://github.com/abhijithvijayan/stargazed
dick318/awesome-starsunknown
oslook/n8n-workflowsunknown
4200 + Workflow Automation Templates are Grouped by Categories/Services for easy navigation
3D-Stories/rawgenticPython
We haven't classified any articles referencing CVE-2026-3304 yet. The external references above still apply.