Denial of Service in @fastify/busboy via Prototype Pollution
An unauthenticated remote attacker can trigger a Denial of Service (DoS) in Node.js applications using @fastify/busboy by submitting crafted multipart/form-data headers naming '__proto__' or 'constructor'.
CVE search metadata
CVE search record: CVE-2026-19481. Severity: high. CVSS: 7.5. EPSS: 0.49%. KEV: no. Product: @fastify/busboy (>= 1.0.0, < 3.2.1). Brief: Denial of Service in @fastify/busboy via Prototype Pollution. Brief link: https://feed.craftedsignal.io/briefs/2026-10-fastify-busboy-dos/
The @fastify/busboy library, a popular Node.js multipart form data parser, contains a critical vulnerability tracked as CVE-2026-19481. The flaw resides in the library's multipart header parser, which stores part-header names directly on a plain JavaScript object without appropriate validation. An attacker can supply a malicious header name, specifically 'proto' or 'constructor', which resolves to inherited JavaScript object properties instead of the expected array. This discrepancy causes the parser to execute 'this.header[h].push', resulting in a 'TypeError: this.header[h].push is not a function'. If the application does not explicitly catch the error event or wrap the stream methods in a try/catch block, the resulting exception can cause the Node.js process to crash, facilitating a remote Denial of Service attack. This vulnerability affects all versions from 1.0.0 up to, but not including, 3.2.1.
Impact
The vulnerability allows unauthenticated remote attackers to terminate Node.js processes handling multipart file uploads or form submissions. This impacts any application using @fastify/busboy for processing incoming web requests. If the application environment lacks robust supervisor processes to auto-restart the application, the service will remain unavailable, resulting in a complete denial of service for the affected component.
Recommendation
Prioritized actions for engineering and security teams:
- Update the @fastify/busboy dependency to version 3.2.1 or later immediately to incorporate the upstream patch.
- For legacy deployments where patching is delayed, ensure all busboy stream instances have a registered 'error' event listener to prevent process termination on parser failure.
- Audit application code for direct usage of 'write()' or 'end()' methods on Busboy instances and wrap these calls in 'try/catch' blocks.
Immediate actions
Upgrade @fastify/busboy to version 3.2.1 or later
Mitigations
Add error event listeners to all instances of busboy streams
CVE-2026-19481