@fastify/busboy vulnerabilities
CVEs whose affected-version data names the @fastify/busboy package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-19481High· 7.5@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
▾ Twilightfastify · @fastify/busboyEPSS 0.49%via GHSA
CVE-2026-19484High· 7.5@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
▾ Twilightfastify · @fastify/busboyEPSS 0.61%via GHSA