chiprook
← Security
SecurityOctober 3, 2026, 11:31

CVE-2026-19484: DoS flaw in @fastify/busboy via Boyer-Moore-Horspool integer wrap-around

@fastify/busboy versions 3.1.0 through 3.2.0 contain an unauthenticated remote denial-of-service vulnerability (CVSS 7.5). An integer wrap-around in the Boyer-Moore-Horspool implementation causes an infinite loop when parsing a 252-byte multipart boundary, stalling the Node.js event loop and maxing out CPU. It is fixed in 3.2.1.

CVE-2026-19484: DoS flaw in @fastify/busboy via Boyer-Moore-Horspool integer wrap-around
#Node.js#Fastify
Read next
Security

CVE-2026-84428: Schema Validation Bypass in Fastify Header Normalization

Security

CVE-2026-76442: Unbounded Input in Cisco Secure Email Gateway Causes DoS

Security

CVE-2026-63349: Privilege Dropping Bypass and DoS in AnyIO Subprocess Module

AI

Epoch AI: AI costs are falling 13x per year, faster than Moore's Law