{"api_version":"v1","generated_at":"2026-10-08T12:40:00+00:00","product":{"cve_count":7,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-multer-multer-2909bfffddba","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/multer","name":"multer","next_cursor":null,"observations":[{"affected":"multer: 2.2.0 < 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-88932","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-88932","fixed":"multer: 2.4.0","last_modified":"2026-09-14T10:29:12.674Z","patch_url":"https://github.com/expressjs/multer/security/advisories/GHSA-3pph-fpjx-jg34","primary_source":"","published":"2026-09-14T08:46:12.896Z"},{"affected":"multer: < 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-82333","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82333","fixed":"multer: 2.3.0","last_modified":"2026-08-31T18:39:14.067Z","patch_url":"https://github.com/expressjs/multer/security/advisories/GHSA-535w-7cp7-47q4","primary_source":"","published":"2026-08-28T20:12:21.355Z"},{"affected":"multer: < 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-77078","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77078","fixed":"multer: 2.3.0","last_modified":"2026-08-31T18:40:24.545Z","patch_url":"https://github.com/expressjs/multer/security/advisories/GHSA-wc9g-mqfw-jrwm","primary_source":"","published":"2026-08-28T20:03:23.114Z"},{"affected":"multer: < 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-77063","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77063","fixed":"multer: 2.3.0","last_modified":"2026-08-31T18:40:55.632Z","patch_url":"https://github.com/expressjs/multer/security/advisories/GHSA-qvfw-j98x-7q72","primary_source":"","published":"2026-08-28T19:54:58.473Z"},{"affected":"multer: 2.2.0 < 2.3.0","affected_versions_present":true,"cve_id":"CVE-2026-77037","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77037","fixed":"multer: 2.3.0","last_modified":"2026-08-31T18:41:28.652Z","patch_url":"https://github.com/expressjs/multer/security/advisories/GHSA-qfvm-cv95-jqjf","primary_source":"","published":"2026-08-28T19:44:23.501Z"},{"affected":"2.0.0-alpha.1 < 2.2.0; 3.0.0-alpha.1 < 3.0.0-alpha.2","affected_versions_present":true,"cve_id":"CVE-2026-5038","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-5038","fixed":"2.2.0; 3.0.0-alpha.2","last_modified":"2026-06-15T16:07:45.114Z","patch_url":"https://github.com/expressjs/multer/security/advisories/GHSA-3p4h-7m6x-2hcm","primary_source":"","published":"2026-06-15T14:23:24.230Z"},{"affected":"1.0.0 < 2.2.0; 3.0.0-alpha.1 < 3.0.0-alpha.2","affected_versions_present":true,"cve_id":"CVE-2026-5079","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-5079","fixed":"2.2.0; 3.0.0-alpha.2","last_modified":"2026-06-15T16:00:43.955Z","patch_url":"https://github.com/expressjs/multer/security/advisories/GHSA-72gw-mp4g-v24j","primary_source":"","published":"2026-06-15T13:56:45.520Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"multer"}}
