OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-19484: @fastify/busboy vulnerable to Denial of Service via oversized multipart boundary

GitHub Advisories · officialPublished Oct 2, 2026Risk 37/100

### Impact Versions of `@fastify/busboy` from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a `Uint8Array(256)`. A multipart boundary of exactly 252 bytes makes the search needle 256 bytes, and the table entry wraps to zero, so a crafted request keeps the search in a CPU-bound loop and stalls the Node.js event loop. An unauthenticated client can trigger this with a single small request. Applications that use `@fastify/busboy` to parse multipart/form-data, directly or through `@fastify/multipart`, are affected. ### Patches Fixed in version 3.2.1. ### Workarounds Validate the multipart boundary before parsing and reject any boundary longer than the RFC 2046 limit of 70 characters (for example at a reverse proxy or in an onRequest hook). Upgrading to 3.2.1 removes the issue.

Upgrade affected packages to a patched version: @fastify/busboy 3.2.1.

Vendor
Not specified
Product
@fastify/busboy
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source