HIGH🇵🇱 Wersja polska

CVE-2026-19481

CVSS 7.5v3.1pub. 2026-08-13upd. 2026-09-03

@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed in @fastify/busboy 3.2.1, which creates the header object with a null prototype. Users should upgrade to 3.2.1.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Fastify Fastify\/busyboy

    APP
    Fastify
    1.0.0 – 3.2.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2026-19484HIGH7.5same product

@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated att...

CVE-2026-18248CRITICAL9.1PL ✓same vendor

Fałszowanie kontekstu Lambda w @fastify/aws-lambda — pełny bypass autoryzacji

CVE-2026-16117CRITICAL10.0PL ✓same vendor

Pominięcie rewrite prefiksu URL w @fastify/http-proxy – dostęp do ukrytych zasobów

CVE-2026-14198CRITICAL9.1PL ✓same vendor

Fastify/Middie: pominięcie middleware przez zakodowany slash w URL

CVE-2026-6556CRITICAL9.1PL ✓same vendor

Pominięcie middleware w @fastify/express — obejście uwierzytelniania