CVE-2026-18549Disclosure(fastify / fastify-multipart)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fastify fastify-multipart systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the client then aborts the connection before sending the terminating boundary, the abort cleanup finds no stream to destroy, so saveRequestFiles() never settles, the request handler hangs, and the temporary file already written to disk is never cleaned up. An unauthenticated client can repeat this to permanently leak temporary files and suspended handler executions, leading to disk and event-loop exhaustion. The issue is fixed in @fastify/multipart 10.1.1. Users should upgrade to 10.1.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-664

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify-multipart

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-08-15); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
fastify-multipart

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-08-15: 3Mentions · 2026-08-16: 2Mentions · 2026-08-17: 1Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-15: 3Technical Details · 2026-08-16: 2Technical Details · 2026-08-17: 108-1508-1608-17
Signal classification3 categories
Disclosure
233.3%
General
233.3%
Patch
233.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-153
Disclosure1General1Patch1
2026-08-162
Disclosure1Patch1
2026-08-171
General1
Full discourse6 posts
  • HOL@HashgraphOnline
    Disclosure

    BREAKING: CVE-2026-18549 hits @fastify/multipart. An unauthenticated client can cross the fileSize limit, abort before the closing boundary, and leave both a temp file and a hung request handler behind. Repeat it and disk + event-loop capacity disappear. https://t.co/7oXJtiCGJD

    Post summary

    The tweet announces a newly identified CVE in @fastify/multipart, outlining the vulnerability and its impact without indicating active exploitation or available mitigations.

    1201211.4K
    19.2K followersView on X
  • HOL@HashgraphOnline
    Patch

    Affected: >=5.3.0 <10.1.1 Fixed: 10.1.1 CVSS: 7.5 HIGH A related same-day bug, CVE-2026-19474, leaks completed temp files during multipart iteration. Same fix. https://hol.org/blog/cve-2026-18549-fastify-multipart-aborted-upload-dos

    Post summary

    CVE-2026-18549 is a high‑severity multipart upload denial‑of‑service bug in Fastify versions 5.3.0–10.1.0; the issue is fixed in 10.1.1, as announced in the linked blog post.

    00030260
    19.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-18549 @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file… https://www.cve.org/CVERecord?id=CVE-2026-18549

    Post summary

    The text discloses CVE-2026-18549 affecting @fastify/multipart, detailing a file truncation bug in busboy’s fileSize limit, without providing exploits, PoCs, or patches.

    000301.9K
    58.1K followersView on X
  • NewNormal Security@NewScanTeam
    General

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 16 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Time-series monitoring database open to anyone who can reach the port — reads every metric you store, and wipes the history an incident would be rebuilt from (VictoriaMetrics) 📦 JWT check that ignores the key it was handed — a token signed with the app's general secret passes a check that demanded a per-tenant one (fastify CVE-2026-18500) 📦 Aborted uploads that never clean up — an unauthenticated client repeats a half-finished upload until the disk fills (fastify CVE-2026-19474, fastify CVE-2026-18549) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #ExposedInterface #CSO #REDTEAM

    Post summary

    The announcement lists several known CVEs added to NewNormal’s detection engine, offering concise technical summaries without any PoC, exploit code, patch, or evidence of active exploitation.

    0000050
    5 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-18549 @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file… https://www.cve.org/CVERecord?id=CVE-2026-18549 ----- Traducción: CVE-2026-18549 @fa… https://infoflow.cloud`

    Post summary

    The post announces the CVE, lists affected versions, and notes a specific bug related to file size truncation, but offers no exploit code, patch, or evidence of active exploitation.

    0000032
    98 followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in @fastify/multipart@10.1.1 just released! Patches CVE-2026-18549: @fastify/multipart vulnerable to denial of service via aborted upload after fileSize limit https://github.com/fastify/fastify-multipart/security/advisories/GHSA-vmph-573x-85f6

    Post summary

    Fastify’s multipart module (v10.1.1) includes a high‑severity denial‑of‑service bug (CVE‑2026‑18549) that has been fixed in the latest release, providing an immediate patch for affected users.

    00000259
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify-multipart-fastify-

Explore more