CVE-2026-3520 | expressjs multer up to 2.1.0 recursion (GHSA-5528-5vmv-3xc2 / WID-SEC-2026-0903)
A vulnerability was found in expressjs multer up to 2.1.0. It has been declared as problematic. Impacted is an unknown function. Executing a manipulation can lead to uncontrolled recursion.
This vulnerability is registered as CVE-2026-3520. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.