StackRadar

CVE-2026-77063

Low

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
141
of 17,781 indexed, latest versions
Container images
138
deployed by those charts
Fix available
1 of 1
affected package

multer vulnerable to file size limit bypass via async fileFilter race condition

Carried by container images the latest versions of 141 of 17,781 indexed charts deploy, on 138 images.

Affected packageAffected versionsFixed inImages
multernpm0.1.8, 1.3.0, 1.4.1, 1.4.2+9 more2.3.0138
OSV records
GHSA-qvfw-j98x-7q72

Charts affected

141 by stars
ChartLatestAffected imagesRadar Score
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
multer@2.1.1
2.3.0

Open the chart page →

2,756
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
multer@1.4.5-lts.1
2.3.0

Open the chart page →

2,548
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
multer@1.4.5-lts.1
2.3.0

Open the chart page →

3,555
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
multer@2.1.1
2.3.0

Open the chart page →

1,809
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
multer@2.0.2
2.3.0

Open the chart page →

1,490
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
multer@1.4.4-lts.1
2.3.0

Open the chart page →

9,774
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
multer@1.4.5-lts.1
2.3.0

Open the chart page →

7,315
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
multer@1.4.5-lts.1
2.3.0

Open the chart page →

9,668
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
multer@2.1.1
2.3.0

Open the chart page →

4,960
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
multer@2.2.0
2.3.0

Open the chart page →

1,038
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_server:0.3.31a528c794270
multer@1.4.1
2.3.0

Open the chart page →

109,294
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
multer@1.4.4-lts.1
2.3.0

Open the chart page →

6,982
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
multer@1.4.4-lts.1
2.3.0

Open the chart page →

4,219
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
multer@2.2.0
2.3.0

Open the chart page →

1,038
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
multer@1.4.5-lts.2
2.3.0

Open the chart page →

1,811
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
mishtinetwork/operator:latestbb3fe67a5f7c
multer@1.4.4-lts.1
2.3.0

Open the chart page →

3,999
ungatep2p-avs0.1.01 of 3See more

ungate p2p-avs 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
multer@1.4.4-lts.1
2.3.0

Open the chart page →

27,373
prismeai-coreprismeai1.12.12 of 7See more

prismeai-core prismeai 1.12.1

2 of the 7 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
multer@2.2.0
2.3.0
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
multer@2.2.0
2.3.0

Open the chart page →

3,270
recipe-apprecipe-app0.1.01 of 2See more

recipe-app recipe-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
multer@1.4.5-lts.1
2.3.0

Open the chart page →

3,271
redisinsightredisinsightVerified publisher0.1.01 of 1See more

redisinsight redisinsight 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
multer@2.0.2
2.3.0

Open the chart page →

1,038
redisinsightredisinsight-helmVerified publisher0.1.11 of 1See more

redisinsight redisinsight-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
redis/redisinsight:2.46699d341bd329
multer@1.4.4-lts.1
2.3.0

Open the chart page →

1,884
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
multer@1.4.4-lts.1
2.3.0

Open the chart page →

6,282
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
multer@1.4.4-lts.1
2.3.0

Open the chart page →

19,560
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
multer@1.4.5-lts.1
2.3.0

Open the chart page →

5,582
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
multer@2.1.1
2.3.0

Open the chart page →

1,991
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
multer@2.0.1
2.3.0

Open the chart page →

1,313
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
multer@1.4.4-lts.1
2.3.0

Open the chart page →

39,090
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
multer@1.4.4-lts.1
2.3.0

Open the chart page →

5,604
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
multer@1.4.4
2.3.0

Open the chart page →

20,270
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
multer@1.4.5-lts.1
2.3.0

Open the chart page →

2,408
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
multer@2.0.2
2.3.0

Open the chart page →

4,661
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
multer@1.4.5-lts.1
2.3.0

Open the chart page →

2,806
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
multer@1.4.4-lts.1
2.3.0

Open the chart page →

17,323
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
multer@2.2.0
2.3.0

Open the chart page →

5,550
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
multer@2.0.2
2.3.0

Open the chart page →

2,620
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
multer@2.0.2
2.3.0

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
multer@1.4.5-lts.2
2.3.0

Open the chart page →

4,768
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
multer@2.2.0
2.3.0

Open the chart page →

1,787
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
multer@2.0.1
2.3.0

Open the chart page →

5,984
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
multer@1.4.4
2.3.0

Open the chart page →

5,459
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2026-77063.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
multer@1.4.5-lts.1
2.3.0
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
multer@1.4.5-lts.1
2.3.0

Open the chart page →

16,083

Container images carrying it

138 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
redis/redisinsight:3.8:latestb5e19ee240ab
multer@2.0.2
2.3.0
4
assistiot/dlt_api:2.0.0e36a8922fa0c
multer@1.4.5-lts.1
2.3.0
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
multer@2.1.1
2.3.0
3
governify/director:v1.4.0608c6940bb98
multer@1.4.3
2.3.0
2
governify/registry:v3.4.0d3f37f4f8168
multer@1.4.2
2.3.0
2
governify/reporter:v2.2.038595913458f
multer@1.4.2
2.3.0
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
multer@1.4.4-lts.1
2.3.0
2
library/ghost:6.63.0e05bc1169fb2
multer@2.2.0
2.3.0
2
n8nio/n8n:2.36.714c4285bc303
multer@2.2.0
2.3.0
2
n8nio/n8n:2.38.45d9f0cc5672b
multer@2.2.0
2.3.0
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
multer@1.4.4-lts.1
2.3.0
2
requarks/wiki:2:latest68f0d1848261
multer@1.4.4
2.3.0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
multer@1.4.5-lts.1
2.3.0
2
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
multer@1.4.5-lts.1
2.3.0
1
assistiot/dlt_api:2.1.0c8a170683be7
multer@1.4.5-lts.1
2.3.0
1
automatischio/automatisch:0.15.03bace7a12d5f
multer@1.4.5-lts.1
2.3.0
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
multer@1.4.4-lts.1
2.3.0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
multer@1.4.3
2.3.0
1
chocobozzz/peertube:v8.1.5052712130691
multer@2.1.1
2.3.0
1
cryptexlabs/authf:0.12.11189c07411d7c
multer@1.4.4-lts.1
2.3.0
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
multer@1.4.5-lts.2
2.3.0
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
multer@1.4.5-lts.1
2.3.0
1
evoapicloud/evolution-api:latest966625532d90
multer@2.0.2
2.3.0
1
fallenbagel/jellyseerr:latest4538137bc5af
multer@1.4.5-lts.1
2.3.0
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
multer@1.4.5-lts.1
2.3.0
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
multer@2.0.1
2.3.0
1
fiware/idm:8.3.3a1b6ed4ae84f
multer@1.4.4
2.3.0
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
multer@2.1.1
2.3.0
1
glenndehaan/api-mapper:latest6ff6310683bf
multer@1.4.5-lts.1
2.3.0
1
glenndehaan/contentbridge:latest99b9e4f73848
multer@1.4.5-lts.1
2.3.0
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
multer@1.4.2
2.3.0
1
heywood8/redisinsight:2.28.00bc9ab313d37
multer@1.4.4-lts.1
2.3.0
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
multer@1.4.2
2.3.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
multer@1.4.4-lts.1
2.3.0
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
multer@2.2.0
2.3.0
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
multer@1.4.1
2.3.0
1
jakowenko/double-take:1.6.0b858bac9e32a
multer@1.4.3
2.3.0
1
jayfong/yapi:1.10.2163e5d621910
multer@1.3.0
2.3.0
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
multer@1.4.4-lts.1
2.3.0
1
kubebb/component-store:latestfd8ecbd73213
multer@1.4.4-lts.1
2.3.0
1
library/ghost:6.37.01ef2e532ca4d
multer@2.1.1
2.3.0
1
library/ghost:6.25.12654b1e90413
multer@2.1.1
2.3.0
1
library/ghost:6.41.129773d6be407
multer@2.1.1
2.3.0
1
library/ghost:4.37.0767230c0f263
multer@1.4.4
2.3.0
1
library/ghost:6.39.0-alpine77196da4b0df
multer@2.1.1
2.3.0
1
library/ghost:5.79.083f7bf209844
multer@1.4.4
2.3.0
1
library/ghost:6.62.0a7a268bbfb7f
multer@2.2.0
2.3.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
multer@2.1.1
2.3.0
1
linuxserver/overseerr:1.35.06108ed066d4a
multer@1.4.5-lts.1
2.3.0
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
multer@1.4.4-lts.1
2.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.