NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2771 most downloaded on npm
Middleware for handling `multipart/form-data`.
Last release 20 days ago
14 Sep 2026
Ships unpredictably
gaps range from 1 weeks to 2.8 years
Nearly every release is documented
notes for 8 of 8 stable releases
47 versions withdrawn
withdrawn after publishing
13 years old
57 releases · first in 2014
Fix CVE-2026-5038 ( GHSA-3p4h-7m6x-2hcm )
Full Changelog: v3.0.0-alpha.1...v3.0.0-alpha.2
One column per quarter.
Nothing published for this version
Fix CVE-2026-88932 ( GHSA-3pph-fpjx-jg34 )
multer finally supports Google Cloud Functions and Firebase 🎉
These platforms read the request body before your code runs, so multer's classic req.pipe(busboy) received nothing: empty req.body, empty req.files, and nearly a decade of duplicated issues.
The new streamHandler option closes that gap: you decide how the body reaches the parser, so the pre-read rawBody just works (see image).
const multer = require('multer')
const upload = multer({
storage: multer.memoryStorage(),
streamHandler: (req, busboy) => {
// Cloud Functions / Firebase expose the pre-read body here
if (req.rawBody) busboy.end(req.rawBody)
else req.pipe(busboy)
}
})
app.post('/upload', upload.single('file'), (req, res) => {
res.json({ name: req.file.originalname, size: req.file.size })
})This landed thanks to community PRs going back to 2017; their authors are credited as co-authors in the release.
Full Changelog: v2.3.0...v2.4.0
filename to LIMIT_FILE_SIZE and LIMIT_UNEXPECTED_FILE errors (#1416)limits, called with the request, to set limits per request (#1133)flush option to DiskStorage to fsync files before the callback runs (#1458)defCharset, highWaterMark and fileHwm options (#1465)streamHandler option to feed busboy from pre-consumed bodies (Google Cloud Functions, Firebase) (#1466)multer.diskStorage() to be called without options (#1471)%0A, %0D, %22) in field names, matching file.originalname since 2.3.0: req.body keys, file.fieldname and err.field now carry the real name. If you matched the escaped spelling as a workaround, use the real name now (#1473)err.filename on LIMIT_FILE_SIZE errors, matching file.originalname (#1478)limits values at construction time; a float limit silently disabled the check (#1395, #1335)limits.parts parts; LIMIT_PART_COUNT now fires only when the limit is exceeded. If you set parts one higher to work around this, you can drop the extra one (#1446)fileFilter no longer count towards maxCount (#1426)LIMIT_UNEXPECTED_FILE message to "Unexpected file field" (#426)concat-stream dependency (#1356)Fix CVE-2026-77078 ( GHSA-wc9g-mqfw-jrwm )
Full Changelog: v2.2.0...v2.3.0
MulterError codes INVALID_FIELD_NAME and STREAM_DESTROYEDlimits.fieldArrayIndexLimit to bound numeric array indexes in field names (#1438)limits.fileSize (#1407)AsyncLocalStorage) when calling next() (#1124)%0A, %0D, %22) in file.originalname (#1421)fileFilter invokes its callback more than once (#1427)MulterError codes without a mapping (#1448)preservePath and parts, use crypto.randomBytes in the DiskStorage example (#1414, #1430, #1436)Fix CVE-2026-5038 ( GHSA-3p4h-7m6x-2hcm )
Full Changelog: v2.1.1...v2.2.0
Fix CVE-2026-3520 ( GHSA-5528-5vmv-3xc2 )
Full Changelog: v2.1.0...v2.1.1
Fix CVE-2026-2359 ( GHSA-v52c-386h-88mc )
Full Changelog: v2.0.2...v2.1.0
defParamCharset option for UTF-8 filename support (#1210)Fix CVE-2025-7338 ( GHSA-fjgf-rc76-4x9p )
Fix CVE-2025-48997 ( GHSA-g5hg-p3ph-g8qg )
ubuntu-latest as default runner by @UlisesGascon in #1308Full Changelog: v2.0.0...v2.0.1
Fix CVE-2025-47935 ( GHSA-44fp-w29j-9vj5 )
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix out-of-band error event from busboy
- No changes
Bugfix: Handle missing field names
Bugfix: Bump busboy to fix CVE-2022-24434
Bugfix: Avoid deprecated pseudoRandomBytes function
Docs: Add Russian translation for README
Bugfix: Make sure that req.file.buffer always is a Buffer
Feature: Make Multer errors inherit from MulterError
Bugfix: Bump vulnerable dependency
Feature: Expose preservePath option
Bugfix: Prevent Multiple Errors from Crashing
Feature: add .none() for accepting only fields
Feature: accept any file, regardless of fieldname
Bugfix: always report limit errors
Bugfix: drain the stream before considering request done
Bugfix: propagate all errors from busboy
Bugfix: ensure file order is correct
Bugfix: don't hang when hitting size limit
Bugfix: decrement pending writes on error
- Introduce storage engines - Specify expected fields - Follow the W3C JSON form spec
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →