• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

zwave-js / zwave-js-ui / 36532128763
13%

Build:
DEFAULT BRANCH: master
Ran 29 Sep 2026 06:39AM UTC
Jobs 1
Files 50
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

29 Sep 2026 06:38AM UTC coverage: 13.161%. Remained the same
36532128763

push

github

web-flow
chore(deps): update dependency multer to v2.4.0 (#4837)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [multer](https://redirect.github.com/expressjs/multer) | [`2.3.0` →
`2.4.0`](https://renovatebot.com/diffs/npm/multer/2.3.0/2.4.0) |
![age](https://developer.mend.io/api/mc/badges/age/npm/multer/2.4.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/multer/2.3.0/2.4.0?slim=true)
|

---

### multer vulnerable to Denial of Service via orphaned disk writes on
aborted uploads
[CVE-2026-88932](https://nvd.nist.gov/vuln/detail/CVE-2026-88932) /
[GHSA-3pph-fpjx-jg34](https://redirect.github.com/advisories/GHSA-3pph-fpjx-jg34)

<details>
<summary>More information</summary>

#### Details
##### Impact

Multer's `diskStorage` can leave complete, orphaned files on disk when a
multipart upload is aborted in the brief window before the storage
engine assigns the file path. This is an incomplete fix of
CVE-2026-5038: the earlier cleanup removes only in-flight uploads that
already have a path, so an upload aborted inside that window is written
to disk with nothing left to remove it, and the application is not given
a handle to clean it up. An unauthenticated attacker sending aborted
requests to any route backed by disk storage can accumulate orphaned
files until the upload directory or the shared system temporary
directory is exhausted. An asynchronous `destination` or `filename`
widens the window.

##### Patches

Users should upgrade to `2.4.0` or higher.

##### Workarounds

None.

#### Severity
- CVSS Score: 5.3 / 10 (Medium)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L`

#### References
-
[https://github.com/expressjs/multer/security/advisories/GHSA-3pph-fpjx-jg34](https://redirect.github.com/expressjs/multer/security/advisories/GHSA-3pph-fpjx-jg34)
-
[https://... (continued)

537 of 4566 branches covered (11.76%)

Branch coverage included in aggregate %.

991 of 7044 relevant lines covered (14.07%)

2.2 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36532128763.1 29 Sep 2026 06:39AM UTC 50
13.16
GitHub Action Run
Source Files on build 36532128763
  • Tree
  • List 50
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • 99f05667 on github
  • Prev Build on master (#36406517592)
  • Next Build on master (#36542665559)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc