<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:fastify:fastify\/Busyboy:*:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afastifyfastify%5C/busyboynode.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 04:50:34 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afastifyfastify%5C/busyboynode.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service in @fastify/busboy via Prototype Pollution</title><link>https://feed.craftedsignal.io/briefs/2026-10-fastify-busboy-dos/</link><pubDate>Sat, 03 Oct 2026 04:50:34 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fastify-busboy-dos/</guid><description>An unauthenticated remote attacker can trigger a Denial of Service (DoS) in Node.js applications using @fastify/busboy by submitting crafted multipart/form-data headers naming '__proto__' or 'constructor'.</description><content:encoded><![CDATA[<p>The @fastify/busboy library, a popular Node.js multipart form data parser, contains a critical vulnerability tracked as CVE-2026-19481. The flaw resides in the library's multipart header parser, which stores part-header names directly on a plain JavaScript object without appropriate validation. An attacker can supply a malicious header name, specifically '<strong>proto</strong>' or 'constructor', which resolves to inherited JavaScript object properties instead of the expected array. This discrepancy causes the parser to execute 'this.header[h].push', resulting in a 'TypeError: this.header[h].push is not a function'. If the application does not explicitly catch the error event or wrap the stream methods in a try/catch block, the resulting exception can cause the Node.js process to crash, facilitating a remote Denial of Service attack. This vulnerability affects all versions from 1.0.0 up to, but not including, 3.2.1.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthenticated remote attackers to terminate Node.js processes handling multipart file uploads or form submissions. This impacts any application using @fastify/busboy for processing incoming web requests. If the application environment lacks robust supervisor processes to auto-restart the application, the service will remain unavailable, resulting in a complete denial of service for the affected component.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for engineering and security teams:</p>
<ul>
<li>Update the @fastify/busboy dependency to version 3.2.1 or later immediately to incorporate the upstream patch.</li>
<li>For legacy deployments where patching is delayed, ensure all busboy stream instances have a registered 'error' event listener to prevent process termination on parser failure.</li>
<li>Audit application code for direct usage of 'write()' or 'end()' methods on Busboy instances and wrap these calls in 'try/catch' blocks.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>