HIGH 7.5 GitHub
CVE-2026-19484
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
### Impact
Versions of `@fastify/busboy` from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a `Uint8Array(256)`. A multipart boundary of exactly 252 bytes makes the search needle 256 bytes, and the table entry wraps to zero, so a crafted request keeps the search in a CPU-bound loop and stalls the Node.js event loop. An unauthenticated client can trigger this with a single small request. Applications th
Affected Products
- npm/@fastify/busboy >= 3.1.0, < 3.2.1
References
- https://github.com/advisories/GHSA-xjh9-v7x6-24jw
- https://github.com/fastify/busboy/security/advisories/GHSA-xjh9-v7x6-24jw
- https://nvd.nist.gov/vuln/detail/CVE-2026-19484
- https://github.com/fastify/busboy/commit/632a237e7fb6b3b7a30e0de8fab2ee72ca5bf722
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-10-02 via GitHub. Affected: npm/@fastify/busboy >= 3.1.0, < 3.2.1.
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.