CVE-2026-74866Disclosure(fastify / fastify\/busyboy)

LOWCVSS 5.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch fastify fastify\/busyboy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return line-feed sequence, so a lone carriage return or line feed embedded in a part header is not treated as a line break and is carried verbatim into the parsed Content-Disposition filename and field name handed to the application. An attacker who uploads a file whose filename or field name contains a bare carriage return or line feed can inject control characters into consumers that trust the parser to return clean values, enabling filesystem filename pollution, log forging, or header injection when the value is forwarded to a carriage-return-sensitive sink. All versions of @fastify/busboy up to and including 3.2.1 are affected. The issue is fixed in version 3.2.2, which rejects any header line that still contains a bare carriage return or line feed. Users should upgrade to 3.2.2, and consumers such as @fastify/multipart should bump their @fastify/busboy dependency to pull in the fix.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/busyboy

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
fastify\/busyboy

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-21: 2Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 208-21
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-74866 @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return line-feed seque… https://www.cve.org/CVERecord?id=CVE-2026-74866

    Post summary

    The tweet announces a new CVE‑2026‑74866 affecting @fastify/busboy’s multipart parsing logic, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    000001.2K
    58.0K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in @fastify/busboy@3.2.2 just released! Patches CVE-2026-74866. CRLF injection via multipart Content-Disposition filename and name. https://github.com/fastify/busboy/security/advisories/GHSA-gxm5-99cw-xjw9

    Post summary

    A medium‑severity CRLF injection vulnerability (CVE-2026-74866) in fastify/busboy has been patched in version 3.2.2, with details and advisory posted on GitHub.

    00000231
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/busyboy-node.js-

Explore more