Fastify Fastify-multipart — known CVE vulnerabilities
Every CVE whose affected-product data names Fastify Fastify-multipart, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (5)
CVE-2020-8136 — CVSS 7.5 (high): Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests…
CVE-2021-23597 — CVSS 7.5 (high): This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible to crash the…
CVE-2023-25576 — CVSS 7.5 (high): @fastify/multipart is a Fastify plugin to parse the multipart content-type. Prior to versions 7.4.1 and 6.0.1, @fastify/multipart may…
CVE-2026-18549 — CVSS 7.5 (high): @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy…
CVE-2026-19474 — CVSS 7.5 (high): @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1…