OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-19481: @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header

GitHub Advisories · officialPublished Oct 2, 2026Risk 37/100

### Impact Versions of `@fastify/busboy` from 1.0.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The multipart header parser stores part-header names on a plain JavaScript object, so a part header named `__proto__` or `constructor` resolves to an inherited value that is not an array, and the parser throws `TypeError: this.header[h].push is not a function`. Through the documented `req.pipe(busboy)` integration this surfaces as an `error` event, while direct `write()`/`end()` usage throws synchronously and can terminate the Node.js process if uncaught. The parser runs before application middleware, so any unauthenticated client that can submit multipart/form-data is affected. ### Patches Fixed in version 3.2.1. ### Workarounds Attach an `error` listener to the Busboy stream so the parser failure is handled rather than crashing the process, and wrap direct `write()`/`end()` calls in a try/catch. Upgrading to 3.2.1 removes the failure entirely.

Upgrade affected packages to a patched version: @fastify/busboy 3.2.1.

Vendor
Not specified
Product
@fastify/busboy
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source