What is CVE-2026-19484?
A vulnerability (CVE-2026-19484) in @fastify/busboy multipart form-data parser versions 3.1.0 through 3.2.0 allows a remote unauthenticated attacker to stall the Node.js event loop by crafting a multipart request boundary with a specific length. Users are advised to upgrade to a patched version.
Azərbaycanca: @fastify/busboy multipart form-data parser kitabxanasının 3.1.0-dan 3.2.0-a qədər versiyalarında aşkarlanan CVE-2026-19484 zəifliyi, uzaqdan autentifikasiya olunmamış hücumçunun xüsusi uzunluqda hazırlanmış boundary ilə multipart sorğu göndərərək Node.js hadisə döngəsini (event loop) dayandırmasına imkan verir. İstifadəçilərə tövsiyə olunur ki, kitabxananı zəiflik aradan qaldırılmış ən son versiyaya yeniləsinlər.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
Which versions of @fastify/busboy are affected by CVE-2026-19484?
This vulnerability affects @fastify/busboy versions 3.1.0 through 3.2.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.