CVE-2026-77078Expressjs · Multer
Vulnerability data via NVD (ingested)
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first field uses a very large numeric array index to allocate a maximum-length sparse array, and a second field then pushes past that length, which throws inside the append-field dependency and is not caught by multer. All versions before 2.3.0 are affected, and the issue is a remotely triggerable denial of service. The issue is fixed in multer 2.3.0. Upgrade to multer 2.3.0 to remediate.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-77078product:"Expressjs Multer"http.html:"Multer"More intel sources (5)
vuln:CVE-2026-77078vulnerabilities.cve_id: CVE-2026-77078CVE-2026-77078CVE-2026-77078"CVE-2026-77078" exploit -site:nvd.nist.gov