@fastify/busboy
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @fastify/busboypage 1 of 1
- CVE-2026-19481HIGHCVSS 7.5EG 7.5fixed in 3.2.12026-08-13
@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ o…
- CVE-2026-19484HIGHCVSS 7.5EG 7.5fixed in 3.2.12026-08-13
@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendore…
- CVE-2026-74866MEDIUMCVSS 5.8EG 5.8fixed in 3.2.22026-08-21
@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return line-feed sequence, so a lone carriage return or line feed embedded in a part header is …
Check whether @fastify/busboy is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @fastify/busboy CVEs against the assets you own.
Book a Demo →