Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

CVE-2026-19481: CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy

CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy Vulnerability ID: CVE-2026-19481 CVSS Score: 7.5 Published: 2026-10-02 A critical remote, unauthenticated Denial

CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy

Vulnerability ID: CVE-2026-19481
CVSS Score: 7.5
Published: 2026-10-02

A critical remote, unauthenticated Denial of Service (DoS) vulnerability in @fastify/busboy (<= 3.2.0) allows attackers to crash the Node.js process. By submitting a crafted multipart/form-data request with a header key matching an inherited property of Object.prototype (like proto or constructor), the internal HeaderParser triggers a synchronous TypeError.

TL;DR

Unauthenticated remote attackers can crash Node.js servers using @fastify/busboy by sending a multipart request with proto or constructor in the headers, triggering an unhandled TypeError.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-754 (Variant of CWE-1321 Prototype Pollution via Prototype Lookup Crash)
  • Attack Vector: Network (AV:N)
  • Attack Complexity: Low (AC:L)
  • Privileges Required: None (PR:N)
  • User Interaction: None (UI:N)
  • CVSS v3.1 Score: 7.5 (High)
  • Exploit Status: Proof-of-Concept (PoC) in Test Suite
  • CISA KEV Status: Not Listed

Affected Systems

  • Node.js applications running @fastify/busboy versions >= 1.0.0 and <= 3.2.0
  • Web frameworks utilizing affected versions of @fastify/busboy as a multipart parsing engine (e.g., Fastify, NestJS configurations)
  • @fastify/busboy: >= 1.0.0, <= 3.2.0 (Fixed in: 3.2.1)

Code Analysis

Commit: 957a24b

Fix: protect prototype property names in HeaderParser

Fix: protect prototype property names in HeaderParser

Exploit Details

  • Official Test Suite & Advisory: Official proof-of-concept tests demonstrating process termination upon receipt of prototype-inherited header keys in the multipart payload

Mitigation Strategies

  • Upgrade @fastify/busboy to version >= 3.2.1
  • Configure WAF rules to drop multipart payloads containing proto or constructor header fields
  • Implement robust process monitoring and automatic container restarts (e.g., systemd, pm2, Kubernetes) to recover from crashes

Remediation Steps:

  1. Audit the application package-lock.json, yarn.lock, or pnpm-lock.yaml for transitive usage of @fastify/busboy.
  2. Execute 'npm update @fastify/busboy' or apply selective dependency resolutions to force version 3.2.1.
  3. Deploy edge validation rules to block raw multipart streams with prototype keys prior to reaching the application layer.
  4. Verify the fix by re-running the proof-of-concept curl script against a staging environment.

References

Read the full report for CVE-2026-19481 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.