๐Ÿ” CVE Alert

CVE-2026-19481

HIGH 7.5

@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed in @fastify/busboy 3.2.1, which creates the header object with a null prototype. Users should upgrade to 3.2.1.

CWE CWE-754
Vendor @fastify/busboy
Product @fastify/busboy
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for @fastify/busboy @fastify/busboy

Be the first to know when new high vulnerabilities affecting @fastify/busboy @fastify/busboy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

@fastify/busboy / @fastify/busboy
1.0.0 < 3.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fastify/busboy/security/advisories/GHSA-x8mw-p69m-v3mx cna.openjsf.org: https://cna.openjsf.org/security-advisories.html

Credits

๐Ÿ” kq5y mcollina UlisesGascon