CVE-2026-19474Disclosure(fastify / fastify-multipart)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fastify fastify-multipart systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing between multipart parts. The iterator rejection that occurs between parts falls outside the per-file cleanup path, so an earlier completed file is never removed. An unauthenticated client can repeat this to cause persistent, linear disk consumption, leading to denial of service. This is an incomplete-fix variant of CVE-2025-24033. The issue is fixed in @fastify/multipart 10.1.1. Users should upgrade to 10.1.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-459CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify-multipart

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-08-15); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
fastify-multipart

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-08-15: 3Mentions · 2026-08-16: 1Mentions · 2026-08-17: 1Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-15: 2Technical Details · 2026-08-16: 1Technical Details · 2026-08-17: 108-1508-1608-17
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-153
Disclosure2Patch1
2026-08-161
Patch1
2026-08-171
General1
Full discourse5 posts
  • HOL@HashgraphOnline
    Patch

    Affected: >=5.3.0 <10.1.1 Fixed: 10.1.1 CVSS: 7.5 HIGH A related same-day bug, CVE-2026-19474, leaks completed temp files during multipart iteration. Same fix. https://hol.org/blog/cve-2026-18549-fastify-multipart-aborted-upload-dos

    Post summary

    The post announces a patch for CVE-2026-18549, detailing affected versions and CVSS score, and links to a blog for full disclosure.

    00030260
    19.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19474 @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed … https://www.cve.org/CVERecord?id=CVE-2026-19474

    Post summary

    The text announces CVE‑2026‑19474 affecting fastify/multipart, but omits any details on exploitation, patches, or technical specifics.

    010001.2K
    57.9K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in @fastify/multipart@10.1.1 just released! Patches CVE-2026-19474: @fastify/multipart vulnerable to denial of service via temporary file leak on aborted upload https://github.com/fastify/fastify-multipart/security/advisories/GHSA-62qx-hpj5-j6hc

    Post summary

    Fastify/multipart 10.1.1 has released a patch for CVE‑2026‑19474, fixing a denial‑of‑service vulnerability caused by temporary file leaks during aborted uploads.

    00010295
    5.5K followersView on X
  • NewNormal Security@NewScanTeam
    General

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 16 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Time-series monitoring database open to anyone who can reach the port — reads every metric you store, and wipes the history an incident would be rebuilt from (VictoriaMetrics) 📦 JWT check that ignores the key it was handed — a token signed with the app's general secret passes a check that demanded a per-tenant one (fastify CVE-2026-18500) 📦 Aborted uploads that never clean up — an unauthenticated client repeats a half-finished upload until the disk fills (fastify CVE-2026-19474, fastify CVE-2026-18549) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #ExposedInterface #CSO #REDTEAM

    Post summary

    The post lists new CVEs with brief technical details but omits any PoC, exploit code, active exploitation claims, or patch information.

    0000050
    5 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19474 @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed … https://www.cve.org/CVERecord?id=CVE-2026-19474 ----- Traducción: CVE-2026-19474 @fa… https://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-19474 affecting Fastify’s multipart parser across versions 3.0.0‑10.1.1, noting a potential issue with request.saveRequestFiles() that may leave a state incomplete.

    0000029
    98 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify-multipart-fastify-

Explore more