StackRadar

CVE-2026-3520

High

Advisory

Published 5 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
108
of 17,781 indexed, latest versions
Container images
108
deployed by those charts
Fix available
1 of 1
affected package

Multer Vulnerable to Denial of Service via Uncontrolled Recursion

Carried by container images the latest versions of 108 of 17,781 indexed charts deploy, on 108 images.

Affected packageAffected versionsFixed inImages
multernpm0.1.8, 1.3.0, 1.4.1, 1.4.2+7 more2.1.1108
OSV records
GHSA-5528-5vmv-3xc2

Charts affected

108 by stars
ChartLatestAffected imagesRadar Score
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-3520.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
multer@1.4.5-lts.1
2.1.1

Open the chart page →

2,806
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-3520.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
multer@1.4.4-lts.1
2.1.1

Open the chart page →

17,323
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-3520.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
multer@2.0.2
2.1.1

Open the chart page →

2,620
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-3520.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
multer@2.0.2
2.1.1

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-3520.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
multer@1.4.5-lts.2
2.1.1

Open the chart page →

4,768
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-3520.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
multer@2.0.1
2.1.1

Open the chart page →

5,984
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-3520.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
multer@1.4.4
2.1.1

Open the chart page →

5,459
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2026-3520.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
multer@1.4.5-lts.1
2.1.1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
multer@1.4.5-lts.1
2.1.1

Open the chart page →

16,083

Container images carrying it

108 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/sct/overseerr:1.35.06197516c9d7b
multer@1.4.5-lts.1
2.1.1
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
multer@1.4.5-lts.1
2.1.1
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
multer@1.4.5-lts.2
2.1.1
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
multer@1.4.4-lts.1
2.1.1
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
multer@2.0.1
2.1.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
multer@1.4.5-lts.1
2.1.1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
multer@1.4.4-lts.1
2.1.1
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
multer@2.0.2
2.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.