Disclosure summary
### Impact Versions of `@fastify/busboy` from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a `Uint8Array(256)`. A multipart boundary of exactly 252 bytes makes the search needle 256 bytes, and the table entry wraps to zero, so a crafted request keeps the search in a CPU-bound loop and stalls the Node.js event loop. An unauthenticated client can trigger this with a single small request. Applications that use `@fastify/busboy` to parse multipart/form-data, directly or through `@fastify/multipart`, are affected. ### Patches Fixed in version 3.2.1. ### Workarounds Validate the multipart boundary before parsing and reject any boundary longer than the RFC 2046 limit of 70 characters (for example at a reverse proxy or in an onRequest hook). Upgrading to 3.2.1 removes the issue.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-xjh9-v7x6-24jw
Open original source · Updated Oct 02, 2026
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @fastify/busboy | >= 3.1.0, < 3.2.1 | 3.2.1 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-02T19:16:17-04:00
MODIFIED 2026-10-02T19:17:29-04:00
INGESTED 2026-10-06T11:45:17-04:00