MEDIUM 5.8 GitHub
CVE-2026-74866
@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and name
### Impact
`@fastify/busboy` 3.2.1 and earlier retains a bare carriage return or line feed inside the parsed `Content-Disposition` parameters returned to the application. The multipart header parser ends a header line only on the two-byte `\r\n` sequence, so a lone CR or LF embedded in a part header is carried verbatim into the `filename` and field `name` delivered by the `file` and `field` events. An application that forwards the supplied filename or name into a CR/LF-sensitive sink cannot ant
Affected Products
- npm/@fastify/busboy < 3.2.2
References
- https://github.com/advisories/GHSA-gxm5-99cw-xjw9
- https://github.com/fastify/busboy/security/advisories/GHSA-gxm5-99cw-xjw9
- https://nvd.nist.gov/vuln/detail/CVE-2026-74866
- https://github.com/fastify/busboy/commit/cc7da17c5c88d79c314a9e149a79e5a00a6c23be
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-05 via GitHub. Affected: npm/@fastify/busboy < 3.2.2.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.