Versions of @fastify/busboy from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a Uint8Array(256). A multipart boundary of exactly 252 bytes makes the search needle 256 bytes, and the table entry wraps to zero, so a crafted request keeps the search in a CPU-bound loop and stalls the Node.js event loop. An unauthenticated client can trigger this with a single small request. Applications that use @fastify/busboy to parse multipart/form-data, directly or through @fastify/multipart, are affected.
Fixed in version 3.2.1.
Validate the multipart boundary before parsing and reject any boundary longer than the RFC 2046 limit of 70 characters (for example at a reverse proxy or in an onRequest hook). Upgrading to 3.2.1 removes the issue.
{
"cwe_ids": [
"CWE-1322",
"CWE-835"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-02T23:16:17Z",
"nvd_published_at": "2026-08-13T10:17:11Z",
"severity": "HIGH"
}