CVE-2026-19484: DoS flaw in @fastify/busboy via Boyer-Moore-Horspool integer wrap-around
@fastify/busboy versions 3.1.0 through 3.2.0 contain an unauthenticated remote denial-of-service vulnerability (CVSS 7.5). An integer wrap-around in the Boyer-Moore-Horspool implementation causes an infinite loop when parsing a 252-byte multipart boundary, stalling the Node.js event loop and maxing out CPU. It is fixed in 3.2.1.
- CVSS 7.5, CWE-835, network attack without authentication
- Affects versions 3.1.0–3.2.0, fixed in 3.2.1
- A 252-byte multipart boundary triggers an infinite loop
- PoC available; not in KEV, EPSS 0.00615
Read next
Security