CVE-2026-19481: CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy
CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy Vulnerability ID: CVE-2026-19481 CVSS Score: 7.5 Published: 2026-10-02 A critical remote, unauthenticated Denial
CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy
Vulnerability ID: CVE-2026-19481
CVSS Score: 7.5
Published: 2026-10-02
A critical remote, unauthenticated Denial of Service (DoS) vulnerability in @fastify/busboy (<= 3.2.0) allows attackers to crash the Node.js process. By submitting a crafted multipart/form-data request with a header key matching an inherited property of Object.prototype (like proto or constructor), the internal HeaderParser triggers a synchronous TypeError.
TL;DR
Unauthenticated remote attackers can crash Node.js servers using @fastify/busboy by sending a multipart request with proto or constructor in the headers, triggering an unhandled TypeError.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-754 (Variant of CWE-1321 Prototype Pollution via Prototype Lookup Crash)
- Attack Vector: Network (AV:N)
- Attack Complexity: Low (AC:L)
- Privileges Required: None (PR:N)
- User Interaction: None (UI:N)
- CVSS v3.1 Score: 7.5 (High)
- Exploit Status: Proof-of-Concept (PoC) in Test Suite
- CISA KEV Status: Not Listed
Affected Systems
- Node.js applications running @fastify/busboy versions >= 1.0.0 and <= 3.2.0
- Web frameworks utilizing affected versions of @fastify/busboy as a multipart parsing engine (e.g., Fastify, NestJS configurations)
-
@fastify/busboy: >= 1.0.0, <= 3.2.0 (Fixed in:
3.2.1)
Code Analysis
Commit: 957a24b
Fix: protect prototype property names in HeaderParser
Fix: protect prototype property names in HeaderParser
Exploit Details
- Official Test Suite & Advisory: Official proof-of-concept tests demonstrating process termination upon receipt of prototype-inherited header keys in the multipart payload
Mitigation Strategies
- Upgrade @fastify/busboy to version >= 3.2.1
- Configure WAF rules to drop multipart payloads containing proto or constructor header fields
- Implement robust process monitoring and automatic container restarts (e.g., systemd, pm2, Kubernetes) to recover from crashes
Remediation Steps:
- Audit the application package-lock.json, yarn.lock, or pnpm-lock.yaml for transitive usage of @fastify/busboy.
- Execute 'npm update @fastify/busboy' or apply selective dependency resolutions to force version 3.2.1.
- Deploy edge validation rules to block raw multipart streams with prototype keys prior to reaching the application layer.
- Verify the fix by re-running the proof-of-concept curl script against a staging environment.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-19481
- https://github.com/fastify/busboy/security/advisories/GHSA-x8mw-p69m-v3mx
- https://cna.openjsf.org/security-advisories.html
- https://github.com/fastify/busboy/commit/957a24b66d5915e6d0a6ac988c9dbcee86373e9b
- https://github.com/fastify/busboy/releases/tag/v3.2.1
Read the full report for CVE-2026-19481 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.