@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary (CVE-2026-19484)
@fastify/busboy versions from 3.1.0 up to but not including 3.2.1 are vulnerable to a denial of service (DoS) attack. The vulnerability arises from the handling of multipart boundaries in the streaming multipart search, where a crafted boundary of exactly 252 bytes causes a CPU-bound loop that stalls the Node.js event loop. This can be triggered by an unauthenticated client with a single small request. The issue is fixed in version 3.2.1.
AI Analysis
Technical Summary
The @fastify/busboy package versions >=3.1.0 and <3.2.1 contain a denial of service vulnerability due to improper handling of multipart boundaries. The internal streaming multipart search uses a Uint8Array(256) to store skip distances. When a multipart boundary of exactly 252 bytes is used, the search needle becomes 256 bytes, causing the table entry to wrap to zero. This results in an infinite CPU-bound loop that stalls the Node.js event loop, allowing an unauthenticated attacker to cause a denial of service with a single crafted multipart/form-data request. Applications using @fastify/busboy directly or via @fastify/multipart are affected. The vulnerability is tracked as CVE-2026-19484 and has a CVSS 3.1 score of 7.5 (high severity).
Potential Impact
An unauthenticated attacker can cause a denial of service by sending a specially crafted multipart/form-data request with an oversized multipart boundary. This stalls the Node.js event loop, effectively making the application unresponsive. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Upgrade @fastify/busboy to version 3.2.1 or later, where the vulnerability is fixed. Alternatively, validate the multipart boundary length before parsing and reject any boundary longer than 70 characters (the RFC 2046 limit), for example at a reverse proxy or in an onRequest hook. Upgrading removes the issue entirely.
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary (CVE-2026-19484)
Description
@fastify/busboy versions from 3.1.0 up to but not including 3.2.1 are vulnerable to a denial of service (DoS) attack. The vulnerability arises from the handling of multipart boundaries in the streaming multipart search, where a crafted boundary of exactly 252 bytes causes a CPU-bound loop that stalls the Node.js event loop. This can be triggered by an unauthenticated client with a single small request. The issue is fixed in version 3.2.1.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @fastify/busboy package versions >=3.1.0 and <3.2.1 contain a denial of service vulnerability due to improper handling of multipart boundaries. The internal streaming multipart search uses a Uint8Array(256) to store skip distances. When a multipart boundary of exactly 252 bytes is used, the search needle becomes 256 bytes, causing the table entry to wrap to zero. This results in an infinite CPU-bound loop that stalls the Node.js event loop, allowing an unauthenticated attacker to cause a denial of service with a single crafted multipart/form-data request. Applications using @fastify/busboy directly or via @fastify/multipart are affected. The vulnerability is tracked as CVE-2026-19484 and has a CVSS 3.1 score of 7.5 (high severity).
Potential Impact
An unauthenticated attacker can cause a denial of service by sending a specially crafted multipart/form-data request with an oversized multipart boundary. This stalls the Node.js event loop, effectively making the application unresponsive. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Upgrade @fastify/busboy to version 3.2.1 or later, where the vulnerability is fixed. Alternatively, validate the multipart boundary length before parsing and reject any boundary longer than 70 characters (the RFC 2046 limit), for example at a reverse proxy or in an onRequest hook. Upgrading removes the issue entirely.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-xjh9-v7x6-24jw
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-19484"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ac139a9a43b0b3b89d69ac9
Added to database: 10/03/2026, 17:21:45 UTC
Last enriched: 10/03/2026, 17:38:37 UTC
Last updated: 10/04/2026, 02:49:16 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.