GHSA-x8mw-p69m-v3mx

Suggest an improvement
Source
https://github.com/advisories/GHSA-x8mw-p69m-v3mx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-x8mw-p69m-v3mx/GHSA-x8mw-p69m-v3mx.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-x8mw-p69m-v3mx
Aliases
Downstream
CGA (44)
MINI (1)
Published
2026-10-02T23:16:36Z
Modified
2026-10-02T23:30:04Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
Details

Impact

Versions of @fastify/busboy from 1.0.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The multipart header parser stores part-header names on a plain JavaScript object, so a part header named __proto__ or constructor resolves to an inherited value that is not an array, and the parser throws TypeError: this.header[h].push is not a function. Through the documented req.pipe(busboy) integration this surfaces as an error event, while direct write()/end() usage throws synchronously and can terminate the Node.js process if uncaught. The parser runs before application middleware, so any unauthenticated client that can submit multipart/form-data is affected.

Patches

Fixed in version 3.2.1.

Workarounds

Attach an error listener to the Busboy stream so the parser failure is handled rather than crashing the process, and wrap direct write()/end() calls in a try/catch. Upgrading to 3.2.1 removes the failure entirely.

Database specific
{
    "cwe_ids": [
        "CWE-754"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-02T23:16:36Z",
    "nvd_published_at": "2026-08-13T09:17:12Z",
    "severity": "HIGH"
}
References

Affected packages

npm / @fastify/busboy

Package

Name
@fastify/busboy
View open source insights on deps.dev
Purl
pkg:npm/%40fastify/busboy

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0
Fixed
3.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-x8mw-p69m-v3mx/GHSA-x8mw-p69m-v3mx.json"