Threat Advisory

fastifybusboy Vulnerable to Denial of Service via Oversized Multipart Boundary

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple denial of service vulnerabilities have been identified in the @fastify/busboy multipart form-data parsing library, both carrying a high-severity CVSS score of 7.5. These security flaws enable unauthenticated remote attackers to trigger event loop stalls or unhandled application exceptions using maliciously crafted HTTP requests. Exploitation requires no privileges or user interaction, posing an immediate availability risk to applications handling multipart form inputs. Organizations utilizing affected library versions should prioritize upgrading to the patched release to ensure service stability.

CVE-2026-19484: This vulnerability is an infinite loop condition caused by inefficient skip distance calculation when processing oversized multipart boundaries in affected component versions. An unauthenticated remote attacker can exploit this issue by sending a single, small request with a specifically sized boundary. Successful exploitation stalls the event loop and locks a CPU core, causing complete denial of service for the underlying application process.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple denial of service vulnerabilities have been identified in the @fastify/busboy multipart form-data parsing library, both carrying a high-severity CVSS score of 7.5. These security flaws enable unauthenticated remote attackers to trigger event loop stalls or unhandled application exceptions using maliciously crafted HTTP requests. Exploitation requires no privileges or user interaction, posing an immediate availability risk to applications handling multipart form inputs. Organizations utilizing affected library versions should prioritize upgrading to the patched release to ensure service stability.

CVE-2026-19484: This vulnerability is an infinite loop condition caused by inefficient skip distance calculation when processing oversized multipart boundaries in affected component versions. An unauthenticated remote attacker can exploit this issue by sending a single, small request with a specifically sized boundary. Successful exploitation stalls the event loop and locks a CPU core, causing complete denial of service for the underlying application process.[emaillocker id="1283"]

CVE-2026-19481: This vulnerability stems from improper object property handling when storing header names on a standard object lacking a null prototype. Remote attackers can exploit this flaw by submitting multipart headers bearing prototype property names like constructor or prototype. This triggers a runtime exception during parsing that crashes the process or interrupts request processing, resulting in a denial of service.

Immediate remediation requires updating affected software dependencies to prevent operational disruption and secure web endpoints against automated exploitation. Implementing secure input validation standards further mitigates risks associated with untrusted multipart header fields.

RECOMMENDATION:

We recommend you to update @fastify/busboy to version 3.2.1.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu