Vulnerability GHSA-x8mw-p69m-v3mx

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
10 hours ago
October 02, 2026 at 11:16 PM UTC
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
1.0.0 - 3.2.0
1.0.0 - 3.2.0

Summary

@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header

Details

Impact

Versions of @fastify/busboy from 1.0.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The multipart header parser stores part-header names on a plain JavaScript object, so a part header named __proto__ or constructor resolves to an inherited value that is not an array, and the parser throws TypeError: this.header[h].push is not a function. Through the documented req.pipe(busboy) integration this surfaces as an error event, while direct write()/end() usage throws synchronously and can terminate the Node.js process if uncaught. The parser runs before application middleware, so any unauthenticated client that can submit multipart/form-data is affected.

Patches

Fixed in version 3.2.1.

Workarounds

Attach an error listener to the Busboy stream so the parser failure is handled rather than crashing the process, and wrap direct write()/end() calls in a try/catch. Upgrading to 3.2.1 removes the failure entirely.

Impacted packages

Timeline

Published
10 hours ago
October 02, 2026 at 11:16 PM UTC
Fixed (3.2.1)
1 month ago
August 12, 2026 at 08:05 PM UTC
Last Modified
9 hours ago
October 02, 2026 at 11:30 PM UTC