Fastify Fastify/busyboy — known CVE vulnerabilities
Every CVE whose affected-product data names Fastify Fastify/busyboy, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (3)
CVE-2026-19481 — CVSS 7.5 (high): @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash…
CVE-2026-19484 — CVSS 7.5 (high): @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js…
CVE-2026-74866 — CVSS 5.8 (medium): @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte…