{"id":"GHSA-xjh9-v7x6-24jw","summary":"@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary","details":"### Impact\n\nVersions of `@fastify/busboy` from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a `Uint8Array(256)`. A multipart boundary of exactly 252 bytes makes the search needle 256 bytes, and the table entry wraps to zero, so a crafted request keeps the search in a CPU-bound loop and stalls the Node.js event loop. An unauthenticated client can trigger this with a single small request. Applications that use `@fastify/busboy` to parse multipart/form-data, directly or through `@fastify/multipart`, are affected.\n\n### Patches\n\nFixed in version 3.2.1.\n\n### Workarounds\n\nValidate the multipart boundary before parsing and reject any boundary longer than the RFC 2046 limit of 70 characters (for example at a reverse proxy or in an onRequest hook). Upgrading to 3.2.1 removes the issue.","aliases":["CVE-2026-19484"],"modified":"2026-10-02T23:30:04.172498362Z","published":"2026-10-02T23:16:17Z","database_specific":{"nvd_published_at":"2026-08-13T10:17:11Z","cwe_ids":["CWE-1322","CWE-835"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-02T23:16:17Z"},"references":[{"type":"WEB","url":"https://github.com/fastify/busboy/security/advisories/GHSA-xjh9-v7x6-24jw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19484"},{"type":"WEB","url":"https://github.com/fastify/busboy/commit/632a237e7fb6b3b7a30e0de8fab2ee72ca5bf722"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/fastify/busboy"},{"type":"WEB","url":"https://github.com/fastify/busboy/releases/tag/v3.2.1"}],"affected":[{"package":{"name":"@fastify/busboy","ecosystem":"npm","purl":"pkg:npm/%40fastify/busboy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.1.0"},{"fixed":"3.2.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-xjh9-v7x6-24jw/GHSA-xjh9-v7x6-24jw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}