Vulnerability GHSA-xjh9-v7x6-24jw

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
10 hours ago
October 02, 2026 at 11:16 PM UTC
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
3.1.0 - 3.2.0
3.1.0 - 3.2.0

Summary

@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary

Details

Impact

Versions of @fastify/busboy from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a Uint8Array(256). A multipart boundary of exactly 252 bytes makes the search needle 256 bytes, and the table entry wraps to zero, so a crafted request keeps the search in a CPU-bound loop and stalls the Node.js event loop. An unauthenticated client can trigger this with a single small request. Applications that use @fastify/busboy to parse multipart/form-data, directly or through @fastify/multipart, are affected.

Patches

Fixed in version 3.2.1.

Workarounds

Validate the multipart boundary before parsing and reject any boundary longer than the RFC 2046 limit of 70 characters (for example at a reverse proxy or in an onRequest hook). Upgrading to 3.2.1 removes the issue.

Impacted packages

Timeline

Published
10 hours ago
October 02, 2026 at 11:16 PM UTC
Fixed (3.2.1)
1 month ago
August 12, 2026 at 08:05 PM UTC
Last Modified
9 hours ago
October 02, 2026 at 11:30 PM UTC