What is CVE-2026-19481?
CVE-2026-19481 is a vulnerability in the @fastify/busboy multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker can crash the parser by sending a part header with a prototype-inherited name like __proto__ or constructor. Updating the library to the latest version is recommended to mitigate this issue.
Azərbaycanca: CVE-2026-19481 @fastify/busboy multipart form-data analizatorunda zəiflikdir. 1.0.0-dan 3.2.0-a qədər olan versiyalarda, təcavüzkar __proto__ və ya constructor kimi prototipdən miras alınmış adlarla başlıq göndərərək analizatoru çökdürə bilər. Bu zəifliyi aradan qaldırmaq üçün kitabxananı ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of the @fastify/busboy library are affected by CVE-2026-19481?
Versions 1.0.0 through 3.2.0 are affected.
How can an attacker exploit CVE-2026-19481?
By sending a part header with a prototype-inherited name like __proto__ or constructor to crash the multipart form-data parser.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.