StackRadar

CVE-2026-77078

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
141
of 17,781 indexed, latest versions
Container images
138
deployed by those charts
Fix available
1 of 1
affected package

multer vulnerable to Denial of Service via crafted multipart field names

Carried by container images the latest versions of 141 of 17,781 indexed charts deploy, on 138 images.

Affected packageAffected versionsFixed inImages
multernpm0.1.8, 1.3.0, 1.4.1, 1.4.2+9 more2.3.0138
OSV records
GHSA-wc9g-mqfw-jrwm

Charts affected

141 by stars
ChartLatestAffected imagesRadar Score
dltkvassist-iot-data-integrity-verification0.2.01 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

1 of the 9 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
multer@1.4.5-lts.1
2.3.0

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.01 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

1 of the 9 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.1.0c8a170683be7
multer@1.4.5-lts.1
2.3.0

Open the chart page →

77,706
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
multer@1.4.4-lts.1
2.3.0

Open the chart page →

4,455
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
multer@1.4.5-lts.2
2.3.0
sysnet4admin/colosseum-prm:log5802bfcd7fed
multer@1.4.5-lts.2
2.3.0

Open the chart page →

26,996
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
multer@1.4.5-lts.1
2.3.0

Open the chart page →

3,071
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
multer@2.1.1
2.3.0

Open the chart page →

4,083
node-redcloudnativeapp1.2.21 of 1See more

node-red cloudnativeapp 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
nodered/node-red-docker:0.19.6-v8070643219ea2
multer@1.4.1
2.3.0

Open the chart page →

4,790
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
multer@1.4.4-lts.1
2.3.0

Open the chart page →

3,769
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
multer@2.0.2
2.3.0

Open the chart page →

22,193
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
multer@1.4.5-lts.2
2.3.0

Open the chart page →

4,251
node-redegebackVerified publisher2.0.131 of 1See more

node-red egeback 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
nodered/node-red:5.0.410f40d0a83e7
multer@2.2.0
2.3.0

Open the chart page →

975
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
multer@2.0.1
2.3.0

Open the chart page →

64,489
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
multer@1.4.4
2.3.0

Open the chart page →

3,159
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
multer@2.0.2
2.3.0

Open the chart page →

1,489
flamegabe565Verified publisher0.6.01 of 1See more

flame gabe565 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
pawelmalak/flame:multiarch2.3.19f88b17692a0
multer@1.4.3
2.3.0

Open the chart page →

2,172
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
multer@1.4.3
2.3.0

Open the chart page →

12,222
node-redgeek-cookbookVerified publisher10.3.21 of 1See more

node-red geek-cookbook 10.3.2

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
nodered/node-red:2.2.2e131dcadfe92
multer@1.4.4
2.3.0

Open the chart page →

2,102
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
multer@1.4.4
2.3.0

Open the chart page →

9,019
api-mapperglenndehaanVerified publisher1.2.01 of 1See more

api-mapper glenndehaan 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
glenndehaan/api-mapper:latest6ff6310683bf
multer@1.4.5-lts.1
2.3.0

Open the chart page →

1,158
contentbridgeglenndehaanVerified publisher1.1.01 of 1See more

contentbridge glenndehaan 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
glenndehaan/contentbridge:latest99b9e4f73848
multer@1.4.5-lts.1
2.3.0

Open the chart page →

1,000
Governify-Bluejaygovernify0.1.03 of 12See more

Governify-Bluejay governify 0.1.0

3 of the 12 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
governify/director:v1.4.0608c6940bb98
multer@1.4.3
2.3.0
governify/registry:v3.4.0d3f37f4f8168
multer@1.4.2
2.3.0
governify/reporter:v2.2.038595913458f
multer@1.4.2
2.3.0

Open the chart page →

22,512
Governify-Falcongovernify0.1.04 of 10See more

Governify-Falcon governify 0.1.0

4 of the 10 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
governify/collector-dynamic:v1.3.06d3d1a5b46a9
multer@1.4.2
2.3.0
governify/director:v1.4.0608c6940bb98
multer@1.4.3
2.3.0
governify/registry:v3.4.0d3f37f4f8168
multer@1.4.2
2.3.0
governify/reporter:v2.2.038595913458f
multer@1.4.2
2.3.0

Open the chart page →

24,319
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
multer@1.4.5-lts.1
2.3.0

Open the chart page →

2,950
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
multer@1.4.5-lts.2
2.3.0

Open the chart page →

3,806
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
multer@1.4.2
2.3.0
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
multer@0.1.8
2.3.0
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
multer@1.4.2
2.3.0
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
multer@1.4.2
2.3.0

Open the chart page →

89,959
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
multer@1.4.4-lts.1
2.3.0

Open the chart page →

3,451
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
multer@2.2.0
2.3.0

Open the chart page →

4,018
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
multer@1.4.5-lts.1
2.3.0

Open the chart page →

5,769
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
multer@1.4.5-lts.2
2.3.0

Open the chart page →

739
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
multer@2.2.0
2.3.0

Open the chart page →

2,463
hoppscotchhelmforgeVerified publisher1.1.111 of 2See more

hoppscotch helmforge 1.1.11

1 of the 2 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2026.8.0d50725df661f
multer@2.2.0
2.3.0

Open the chart page →

2,046
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
multer@2.2.0
2.3.0

Open the chart page →

11,042
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
multer@1.4.2
2.3.0

Open the chart page →

4,253
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
multer@1.4.4-lts.1
2.3.0

Open the chart page →

3,614
crypto-watchdoghuseyinnurbaki0.1.01 of 1See more

crypto-watchdog huseyinnurbaki 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
hhaluk/crypto-watchdog:0.4.0a6555953d941
multer@1.4.2
2.3.0

Open the chart page →

2,656
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
multer@1.4.1
2.3.0

Open the chart page →

39,349
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4b760f0d2547
multer@2.2.0
2.3.0

Open the chart page →

781
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
multer@2.1.1
2.3.0

Open the chart page →

3,436
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
multer@1.4.5-lts.2
2.3.0

Open the chart page →

5,826
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
multer@1.3.0
2.3.0

Open the chart page →

6,454
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
multer@1.4.5-lts.1
2.3.0

Open the chart page →

22,589
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
multer@2.1.1
2.3.0

Open the chart page →

3,092
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
multer@1.4.5-lts.1
2.3.0

Open the chart page →

9,783
zwave-js-uik8sonlabVerified publisher0.7.121 of 1See more

zwave-js-ui k8sonlab 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
zwavejs/zwave-js-ui:11.22.314d018bb689e
multer@2.0.2
2.3.0

Open the chart page →

973
redisinsightklicktippVerified publisher0.5.01 of 1See more

redisinsight klicktipp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
redis/redisinsight:3.2.055542a762210
multer@2.0.2
2.3.0

Open the chart page →

1,290
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
visualregressiontracker/api:5.0.11941aeb8c8bf9
multer@1.4.4-lts.1
2.3.0

Open the chart page →

9,098
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
multer@1.4.4
2.3.0

Open the chart page →

4,230
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
multer@1.4.4
2.3.0

Open the chart page →

5,410
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
multer@1.4.4-lts.1
2.3.0

Open the chart page →

2,178
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2026-77078.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
multer@1.4.4-lts.1
2.3.0

Open the chart page →

13,819

Container images carrying it

138 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
redis/redisinsight:3.8:latestb5e19ee240ab
multer@2.0.2
2.3.0
4
assistiot/dlt_api:2.0.0e36a8922fa0c
multer@1.4.5-lts.1
2.3.0
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
multer@2.1.1
2.3.0
3
governify/director:v1.4.0608c6940bb98
multer@1.4.3
2.3.0
2
governify/registry:v3.4.0d3f37f4f8168
multer@1.4.2
2.3.0
2
governify/reporter:v2.2.038595913458f
multer@1.4.2
2.3.0
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
multer@1.4.4-lts.1
2.3.0
2
library/ghost:6.63.0e05bc1169fb2
multer@2.2.0
2.3.0
2
n8nio/n8n:2.36.714c4285bc303
multer@2.2.0
2.3.0
2
n8nio/n8n:2.38.45d9f0cc5672b
multer@2.2.0
2.3.0
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
multer@1.4.4-lts.1
2.3.0
2
requarks/wiki:2:latest68f0d1848261
multer@1.4.4
2.3.0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
multer@1.4.5-lts.1
2.3.0
2
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
multer@1.4.5-lts.1
2.3.0
1
assistiot/dlt_api:2.1.0c8a170683be7
multer@1.4.5-lts.1
2.3.0
1
automatischio/automatisch:0.15.03bace7a12d5f
multer@1.4.5-lts.1
2.3.0
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
multer@1.4.4-lts.1
2.3.0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
multer@1.4.3
2.3.0
1
chocobozzz/peertube:v8.1.5052712130691
multer@2.1.1
2.3.0
1
cryptexlabs/authf:0.12.11189c07411d7c
multer@1.4.4-lts.1
2.3.0
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
multer@1.4.5-lts.2
2.3.0
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
multer@1.4.5-lts.1
2.3.0
1
evoapicloud/evolution-api:latest966625532d90
multer@2.0.2
2.3.0
1
fallenbagel/jellyseerr:latest4538137bc5af
multer@1.4.5-lts.1
2.3.0
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
multer@1.4.5-lts.1
2.3.0
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
multer@2.0.1
2.3.0
1
fiware/idm:8.3.3a1b6ed4ae84f
multer@1.4.4
2.3.0
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
multer@2.1.1
2.3.0
1
glenndehaan/api-mapper:latest6ff6310683bf
multer@1.4.5-lts.1
2.3.0
1
glenndehaan/contentbridge:latest99b9e4f73848
multer@1.4.5-lts.1
2.3.0
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
multer@1.4.2
2.3.0
1
heywood8/redisinsight:2.28.00bc9ab313d37
multer@1.4.4-lts.1
2.3.0
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
multer@1.4.2
2.3.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
multer@1.4.4-lts.1
2.3.0
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
multer@2.2.0
2.3.0
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
multer@1.4.1
2.3.0
1
jakowenko/double-take:1.6.0b858bac9e32a
multer@1.4.3
2.3.0
1
jayfong/yapi:1.10.2163e5d621910
multer@1.3.0
2.3.0
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
multer@1.4.4-lts.1
2.3.0
1
kubebb/component-store:latestfd8ecbd73213
multer@1.4.4-lts.1
2.3.0
1
library/ghost:6.37.01ef2e532ca4d
multer@2.1.1
2.3.0
1
library/ghost:6.25.12654b1e90413
multer@2.1.1
2.3.0
1
library/ghost:6.41.129773d6be407
multer@2.1.1
2.3.0
1
library/ghost:4.37.0767230c0f263
multer@1.4.4
2.3.0
1
library/ghost:6.39.0-alpine77196da4b0df
multer@2.1.1
2.3.0
1
library/ghost:5.79.083f7bf209844
multer@1.4.4
2.3.0
1
library/ghost:6.62.0a7a268bbfb7f
multer@2.2.0
2.3.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
multer@2.1.1
2.3.0
1
linuxserver/overseerr:1.35.06108ed066d4a
multer@1.4.5-lts.1
2.3.0
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
multer@1.4.4-lts.1
2.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.