GHSA-x8mw-p69m-v3mx: High severity npm/@fastify/busboy vulnerability

Published Oct 2, 2026
·
Updated

Impact

Versions of @fastify/busboy from 1.0.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The multipart header parser stores part-header names on a plain JavaScript object, so a part header named proto or constructor resolves to an inherited value that is not an array, and the parser throws TypeError: this.header[h].push is not a function. Through the documented req.pipe(busboy) integration this surfaces as an error event, while direct write()/end() usage throws synchronously and can terminate the Node.js process if uncaught. The parser runs before application middleware, so any unauthenticated client that can submit multipart/form-data is affected.

Patches

Fixed in version 3.2.1.

Workarounds

Attach an error listener to the Busboy stream so the parser failure is handled rather than crashing the process, and wrap direct write()/end() calls in a try/catch. Upgrading to 3.2.1 removes the failure entirely.

Affected Software

1 affected componentFixes available
npm/@fastify/busboy>=1.0.0<3.2.1
3.2.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@fastify/busboy to a version that resolves this vulnerability.

    Fixed in 3.2.1
  2. Upgrade

    Upgrade @fastify/busboy to a version that resolves this vulnerability.

    Fixed in 3.2.1
  3. Compensating control

    Attach an error listener to the Busboy stream and wrap direct write()/end() calls in try/catch so parser failures are handled rather than crashing the process.

Event History

Oct 2, 2026
Advisory Published
via GitHub·11:16 PM
Data Sourced
via GitHub·11:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this denial-of-service condition?

Deployments using @fastify/busboy versions 1.0.0 through versions before 3.2.1 are affected if unauthenticated clients can submit multipart/form-data. The vulnerable parser runs before application middleware, so middleware-based authentication does not prevent the parser from being reached.

2

What does an attacker need to send to trigger the failure?

An attacker only needs to submit a multipart/form-data request containing a part header named __proto__ or constructor. No authentication or user interaction is required.

3

Does the impact differ by integration method?

With the documented req.pipe(busboy) integration, the parser failure is emitted as an error event. With direct write() or end() usage, it throws synchronously and can terminate the Node.js process if the exception is uncaught.

4

What can be done if upgrading is not immediately possible?

Attach an error listener to the Busboy stream so the parser failure is handled rather than crashing the process. For direct write() or end() usage, wrap those calls in try/catch.

5

What version fixes the issue?

Upgrade @fastify/busboy to version 3.2.1. This removes the failure entirely.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203