CVE-2026-74866 with a CVSS score of 5.8 is a vulnerability affecting @fastify/busboy versions < 3.2.2 in @fastify/busboy due to CRLF injection via multipart Content-Disposition filename and name, which can pollute filenames on disk when the upload is saved under its original name, inject forged lines into logs, or inject headers on a downstream hop that does not re-validate CR/LF. Applications using @fastify/busboy directly, or through @fastify/multipart and its consumers, are affected. The vulnerable component is in the file handling layer of the application, where it fails to sanitize filenames properly. An attacker can exploit this flaw by uploading a malicious file with a crafted filename that contains a bare CR or LF, which will be carried verbatim into the filename delivered by the file event. This vulnerability has a medium severity and can have significant business impact if left unaddressed.
We recommend you to update @fastify/busboy to version 3.2.2.[/subscribe_to_unlock_form]
CVE-2026-74866 with a CVSS score of 5.8 is a vulnerability affecting @fastify/busboy versions < 3.2.2 in @fastify/busboy due to CRLF injection via multipart Content-Disposition filename and name, which can pollute filenames on disk when the upload is saved under its original name, inject forged lines into logs, or inject headers on a downstream hop that does not re-validate CR/LF. Applications using @fastify/busboy directly, or through @fastify/multipart and its consumers, are affected. The vulnerable component is in the file handling layer of the application, where it fails to sanitize filenames properly. An attacker can exploit this flaw by uploading a malicious file with a crafted filename that contains a bare CR or LF, which will be carried verbatim into the filename delivered by the file event. This vulnerability has a medium severity and can have significant business impact if left unaddressed.
We recommend you to update @fastify/busboy to version 3.2.2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]