Impact
When multer is configured with an asynchronous fileFilter, the limits.fileSize limit can be bypassed. The 'limit' event is registered inside the async fileFilter callback, so if a file exceeds limits.fileSize before that callback runs, the event is missed and the oversized upload is accepted instead of being rejected with a LIMIT_FILE_SIZE error. Applications that rely on limits.fileSize to reject oversized uploads are affected on all upload methods (.single(), .array(), .fields(), .any()). Uploads using a synchronous fileFilter are not affected.
Patches
Users should upgrade to 2.3.0.
Workarounds
Use a synchronous fileFilter, or validate the uploaded file size after the upload completes.
References
Impact
When
multeris configured with an asynchronousfileFilter, thelimits.fileSizelimit can be bypassed. The'limit'event is registered inside the asyncfileFiltercallback, so if a file exceedslimits.fileSizebefore that callback runs, the event is missed and the oversized upload is accepted instead of being rejected with aLIMIT_FILE_SIZEerror. Applications that rely onlimits.fileSizeto reject oversized uploads are affected on all upload methods (.single(),.array(),.fields(),.any()). Uploads using a synchronousfileFilterare not affected.Patches
Users should upgrade to
2.3.0.Workarounds
Use a synchronous
fileFilter, or validate the uploaded file size after the upload completes.References