Medium · 4.9 Node.js & npm GHSA-x8mw-p69m-v3mx CVE-2026-19481 GHSA-xjh9-v7x6-24jw CVE-2026-19484
Two Denial-of-Service Vulnerabilities Patched in @fastify/busboy Multipart Parser
Two separate CVSS 7.5 Denial of Service vulnerabilities in @fastify/busboy allow unauthenticated attackers to crash or hang Node.js applications via crafted multipart/form-data requests. Both are fixed in version 3.2.1.
AI summary
Two Denial of Service vulnerabilities have been disclosed in @fastify/busboy, a widely used Node.js library for parsing multipart/form-data requests. Both issues can be triggered by an unauthenticated remote attacker without any special permissions or user interaction, and both are resolved in version 3.2.1 of the package. Because the affected parsing logic runs before application-level middleware, any service that accepts multipart form uploads through this library is potentially exposed, whether directly or via @fastify/multipart.
What happened
Two distinct Denial of Service vulnerabilities were disclosed for the @fastify/busboy npm package. CVE-2026-19481 (GHSA-x8mw-p69m-v3mx): The multipart header parser stores part-header names on a plain JavaScript object. If a part header is named `__proto__` or `constructor`, it resolves to an inherited property instead of an array, causing the parser to throw a TypeError. Depending on integration, this surfaces as an `error` event or, in direct write()/end() usage, as a synchronous throw that can crash the Node.js process if left uncaught. CVE-2026-19484 (GHSA-xjh9-v7x6-24jw): The library's vendored streaming multipart search algorithm stores its default skip distance in a fixed-size 256-byte array. A multipart boundary of exactly 252 bytes produces a 256-byte search needle, causing a table entry to wrap to zero. This forces the search into a CPU-bound loop that stalls the Node.js event loop, triggered by a single small request.
Technical cause
CVE-2026-19481 is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions): the parser does not guard against part-header names that collide with JavaScript object prototype properties (`__proto__`, `constructor`), leading to an unhandled type error instead of safe rejection or sanitisation. CVE-2026-19484 is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop): a fixed-size lookup table used in the boundary search algorithm does not correctly handle a boundary length of exactly 252 bytes, causing the skip-distance calculation to wrap and the search loop to fail to terminate efficiently.
Why it matters
Both vulnerabilities carry a CVSS base score of 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), reflecting network-exploitable, low-complexity attacks requiring no privileges or user interaction, with high impact on availability and no impact on confidentiality or integrity. An unauthenticated client that can submit a multipart/form-data request can trigger either issue. Because the multipart parser runs before application middleware, typical authentication or authorization checks do not prevent exploitation.
Who is affected
Applications using @fastify/busboy to parse multipart/form-data are affected, either by using the package directly or indirectly through @fastify/multipart. CVE-2026-19481 affects versions from 1.0.0 up to but not including 3.2.1. CVE-2026-19484 affects versions from 3.1.0 up to but not including 3.2.1. Services accepting file or form uploads from unauthenticated or untrusted clients face the greatest exposure.
Affected versions
@fastify/busboy: CVE-2026-19481 affects versions >= 1.0.0 and < 3.2.1. CVE-2026-19484 affects versions >= 3.1.0 and < 3.2.1. Both vulnerabilities are fixed in version 3.2.1.
Fixes and mitigation
Both vulnerabilities are fixed in @fastify/busboy version 3.2.1. Until the upgrade can be applied, interim workarounds are available for each issue separately. For CVE-2026-19481: attach an `error` event listener to the Busboy stream so parser failures are handled gracefully rather than crashing the process, and wrap direct write()/end() calls in a try/catch block. For CVE-2026-19484: validate the multipart boundary length before parsing and reject any boundary longer than the RFC 2046 limit of 70 characters, for example at a reverse proxy or in an onRequest hook. Upgrading to version 3.2.1 removes both issues entirely and is the recommended long-term fix.
Recommended action
Upgrade @fastify/busboy to version 3.2.1 as soon as possible, including indirect dependencies via @fastify/multipart. If immediate upgrading is not possible, apply the documented workarounds: add error-event handling and try/catch protection around direct stream usage, and enforce boundary-length validation at the request-handling layer.
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
Both vulnerabilities are scored CVSS 7.5 (High), driven by network attack vector, low attack complexity, no required privileges, no user interaction, and a high availability impact with no confidentiality or integrity impact. The PatchBriefing score of 4.9 for each reflects the CVSS base score contribution along with additional weight for unauthenticated remote exploitability and lack of required user interaction. Neither vulnerability is known to be exploited in the wild, and no public exploit code has been reported for either issue at the time of publication.
Affected versions
- @fastify/busboy >= 1.0.0, < 3.2.1
- vulnerable
- ≥ 3.2.1
- patched
- @fastify/busboy >= 3.1.0, < 3.2.1
- vulnerable
- ≥ 3.2.1
- patched
Reported fixes
Both vulnerabilities are fixed in @fastify/busboy version 3.2.1. Until the upgrade can be applied, interim workarounds are available for each issue separately. For CVE-2026-19481: attach an `error` event listener to the Busboy stream so parser failures are handled gracefully rather than crashing the process, and wrap direct write()/end() calls in a try/catch block. For CVE-2026-19484: validate the multipart boundary length before parsing and reject any boundary longer than the RFC 2046 limit of 70 characters, for example at a reverse proxy or in an onRequest hook. Upgrading to version 3.2.1 removes both issues entirely and is the recommended long-term fix.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email