CVE-2026-19481
Last modified
CVE-2026-19481 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed in @fastify/busboy 3.2.1, which creates the header object with a null prototype. Users should upgrade to 3.2.1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fastify | Fastify\/Busyboy | >= 1.0.0, < 3.2.1 |
References
- https://cna.openjsf.org/security-advisories.htmlThird Party Advisory
- https://github.com/fastify/busboy/security/advisories/GHSA-x8mw-p69m-v3mxMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-19481?
How severe is CVE-2026-19481?
How do I fix CVE-2026-19481?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19472A denial-of-service security issue exists within ArmorStart®…8.7
- CVE-2026-19474@fastify/multipart is a multipart form-data parser for Fasti…7.5
- CVE-2026-19475An authenticated user with permission to query a SQL data so…6.5
- CVE-2026-19478GitLab has remediated an issue in GitLab CE/EE affecting all…9.1
- CVE-2026-19479Adobe Experience Manager is affected by a DOM-based Cross-Si…5.4
- CVE-2026-1948The NEX-Forms – Ultimate Forms Plugin for WordPress plugin f…4.3
- CVE-2026-19483IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 throu…5.5
- CVE-2026-19484@fastify/busboy is a multipart form-data parser. In versions…7.5
- CVE-2026-19485A Predictable Resource Name vulnerability in BigQuery Import…9.3
- CVE-2026-19487Perl versions from 5.9.4 before 5.41.9 produce incorrect reg…5.3
- CVE-2026-19489Vulnerability in NetScaler ADC and NetScaler Gateway. This …8.8
- CVE-2026-1949Delta Electronics AS320T has incorrect calculation of the bu…9.8
Are you affected by CVE-2026-19481?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
