LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-19481

fastify · fastify\/busyboy

Published
CVSS7.5
Severityhigh
WeaknessCWE-754
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed

References

← Back to the CVE Tracker

Our coverage of CVE-2026-19481

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-19481.