{"api_version":"v1","generated_at":"2026-10-07T08:45:00+00:00","product":{"cve_count":7,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-expressjs-multer-ee67b2145ebf","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/multer","name":"multer","next_cursor":null,"observations":[{"affected":"< 2.1.1","affected_versions_present":true,"cve_id":"CVE-2026-3520","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3520","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-15T01:03:04.430Z","patch_url":"https://github.com/expressjs/multer/commit/7e66481f8b2e6c54b982b34c152479e096ce2752","primary_source":"","published":"2026-03-04T16:17:18.962Z"},{"affected":"0.0.0 < 2.1.0","affected_versions_present":true,"cve_id":"CVE-2026-3304","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3304","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-15T01:07:21.678Z","patch_url":"https://github.com/expressjs/multer/security/advisories/GHSA-xf7r-hgr6-v32p","primary_source":"","published":"2026-02-27T15:44:37.187Z"},{"affected":"0.0.0 < 2.1.0","affected_versions_present":true,"cve_id":"CVE-2026-2359","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-2359","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-15T01:18:16.179Z","patch_url":"https://github.com/expressjs/multer/security/advisories/GHSA-v52c-386h-88mc","primary_source":"","published":"2026-02-27T15:42:08.088Z"},{"affected":"1.4.4-lts.1 < 2.0.2","affected_versions_present":true,"cve_id":"CVE-2025-7338","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-7338","fixed":"For more about Red Hat Developer Hub, see References links","last_modified":"2025-07-17T16:48:43.154Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-7338","primary_source":"","published":"2025-07-17T15:26:45.427Z"},{"affected":">= 1.4.4-lts.1, < 2.0.1","affected_versions_present":true,"cve_id":"CVE-2025-48997","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48997","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-06-03T18:30:13.178Z","patch_url":"","primary_source":"","published":"2025-06-03T18:21:59.527Z"},{"affected":">=1.4.4-lts.1, <2.0.0","affected_versions_present":true,"cve_id":"CVE-2025-47944","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-47944","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-20T13:13:49.579Z","patch_url":"","primary_source":"","published":"2025-05-19T19:20:45.401Z"},{"affected":"< 2.0.0","affected_versions_present":true,"cve_id":"CVE-2025-47935","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-47935","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-27T20:28:27.244Z","patch_url":"","primary_source":"","published":"2025-05-19T19:18:38.018Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"expressjs"}}
