{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afastifyfastify%5C/busyboynode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fastify:busboy:*:*:*:*:*:node.js:*:*","cpe:2.3:a:fastify:fastify\\/busyboy:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-19481"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@fastify/busboy (\u003e= 1.0.0, \u003c 3.2.1)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Fastify"],"content_html":"\u003cp\u003eThe @fastify/busboy library, a popular Node.js multipart form data parser, contains a critical vulnerability tracked as CVE-2026-19481. The flaw resides in the library's multipart header parser, which stores part-header names directly on a plain JavaScript object without appropriate validation. An attacker can supply a malicious header name, specifically '\u003cstrong\u003eproto\u003c/strong\u003e' or 'constructor', which resolves to inherited JavaScript object properties instead of the expected array. This discrepancy causes the parser to execute 'this.header[h].push', resulting in a 'TypeError: this.header[h].push is not a function'. If the application does not explicitly catch the error event or wrap the stream methods in a try/catch block, the resulting exception can cause the Node.js process to crash, facilitating a remote Denial of Service attack. This vulnerability affects all versions from 1.0.0 up to, but not including, 3.2.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated remote attackers to terminate Node.js processes handling multipart file uploads or form submissions. This impacts any application using @fastify/busboy for processing incoming web requests. If the application environment lacks robust supervisor processes to auto-restart the application, the service will remain unavailable, resulting in a complete denial of service for the affected component.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the @fastify/busboy dependency to version 3.2.1 or later immediately to incorporate the upstream patch.\u003c/li\u003e\n\u003cli\u003eFor legacy deployments where patching is delayed, ensure all busboy stream instances have a registered 'error' event listener to prevent process termination on parser failure.\u003c/li\u003e\n\u003cli\u003eAudit application code for direct usage of 'write()' or 'end()' methods on Busboy instances and wrap these calls in 'try/catch' blocks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T04:50:34Z","date_published":"2026-10-03T04:50:34Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fastify-busboy-dos/","summary":"An unauthenticated remote attacker can trigger a Denial of Service (DoS) in Node.js applications using @fastify/busboy by submitting crafted multipart/form-data headers naming '__proto__' or 'constructor'.","title":"Denial of Service in @fastify/busboy via Prototype Pollution","url":"https://feed.craftedsignal.io/briefs/2026-10-fastify-busboy-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:fastify:fastify\\/Busyboy:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}