Race condition In multer
Description
multer vulnerable to file size limit bypass via async fileFilter race condition
Impact
When multer is configured with an asynchronous fileFilter, the limits.fileSize limit can be bypassed. The 'limit' event is registered inside the async fileFilter callback, so if a file exceeds limits.fileSize before that callback runs, the event is missed and the oversized upload is accepted instead of being rejected with a LIMIT_FILE_SIZE error. Applications that rely on limits.fileSize to reject oversized uploads are affected on all upload methods (.single(), .array(), .fields(), .any()). Uploads using a synchronous fileFilter are not affected.
Patches
Users should upgrade to 2.3.0.
Workarounds
Use a synchronous fileFilter, or validate the uploaded file size after the upload completes.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
rpm rhel7 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
npm | 2.3.0 |
Aliases
References