CVE-2026-19484: @fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry byte array, and a boundary of exactly 252 bytes makes the search needle 256 bytes, which truncates the default skip distance to zero and turns the search into a CPU bound loop on a small body. A single small request can keep one core busy and deny service to other requests handled by the same process. The issue is fixed in @fastify/busboy 3.2.1, which widens the skip table so the skip distance is preserved. Users should upgrade to 3.2.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@fastify/busboyto a version that resolves this vulnerability.Fixed in 3.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19484?
CVE-2026-19484 has a high severity rating of 7.5.
How do I fix CVE-2026-19484?
To fix CVE-2026-19484, you should update @fastify/busboy to version 3.2.1 or later.
What type of vulnerability is CVE-2026-19484?
CVE-2026-19484 is a Denial of Service vulnerability affecting the @fastify/busboy package.
Which versions of @fastify/busboy are affected by CVE-2026-19484?
Versions 3.1.0 through 3.2.0 of @fastify/busboy are affected by CVE-2026-19484.
Can an attacker exploit CVE-2026-19484 remotely?
Yes, a remote unauthenticated attacker can exploit CVE-2026-19484 by sending a specially crafted multipart request.