CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-19484

CVE-2026-19484: Remote Denial of Service via Boyer-Moore-Horspool Integer Wrap-around in @fastify/busboy

Alon Barad
Alon Barad
Software Engineer

Oct 3, 2026·6 min read·6 visits

Executive Summary (TL;DR)

A vulnerability in @fastify/busboy causes a Node.js event loop stall and 100% CPU utilization when parsing a crafted HTTP request with a 252-byte multipart boundary, causing a complete denial of service.

An unauthenticated remote denial of service vulnerability exists in @fastify/busboy versions 3.1.0 through 3.2.0. The vulnerability is caused by an integer wrap-around in the Boyer-Moore-Horspool algorithm implementation inside the sbmh submodule when initializing skip distances. When processing a specific boundary of 252 bytes, the parser triggers an infinite loop, stalling the single-threaded Node.js event loop and exhausting CPU resources.

Vulnerability Overview

The @fastify/busboy library is a standard streaming parser designed to process multipart/form-data payloads in Node.js applications. This parser handles incoming file uploads and form fields in a non-blocking stream, making it highly critical for APIs accepting file inputs. Because Node.js utilizes a single-threaded architecture, any blocking or CPU-bound computation in core parsing dependencies impacts the scalability of the entire host application.

CVE-2026-19484 represents an algorithmic denial of service vulnerability in the Boyer-Moore-Horspool string search algorithm utilized within the library's streamsearch submodule. When processing specially crafted multipart headers, the parser is forced into an infinite loop, stalling the Node.js event loop completely. This vulnerability allows an unauthenticated, remote attacker to starve application resources by sending a single, minimal request.

Because the underlying event loop is blocked, the server becomes incapable of accepting new TCP connections or processing outstanding requests. The impact remains isolated to the availability of the host service, meaning confidentiality and integrity are not compromised, though service restoration requires manual intervention or an automated process restart.

Root Cause Analysis

The core defect resides within deps/streamsearch/sbmh.js, which implements the Boyer-Moore-Horspool string search algorithm for pattern matching against multipart boundaries. This algorithm precomputes a bad-character shift table (known as the occurrence table) that defines how far the window can shift forward when a character mismatch occurs. The default shift distance for mismatching characters is designated as the length of the needle pattern itself.

In the vulnerable implementation, the occurrence table is backed by a Uint8Array of size 256. When a multipart boundary of exactly 252 bytes is supplied, the library prepends standard formatting delimiters, expanding the needle pattern to exactly 256 bytes. When initialization code attempts to populate the occurrence table using the .fill(256) method, an 8-bit integer wrap-around occurs because the maximum value for a Uint8Array element is 255.

Consequently, the value 256 overflows to 0 inside the array elements ($256 \pmod{256} = 0$). Any mismatch on a byte mapped to these zeroed entries instructs the search algorithm to advance the matching window by exactly 0 bytes. This creates a loop with an unreachable exit condition (CWE-835), forcing the single-threaded Node.js event loop to execute the identical comparison at the same offset perpetually.

Code Analysis and Patch Walkthrough

The vulnerability was remediated in commit 632a237e7fb6b3b7a30e0de8fab2ee72ca5bf722 by altering the storage representation of the occurrence table. The patch changes the backing array of the table from an 8-bit unsigned integer array to a 16-bit unsigned integer array, raising the maximum boundary capacity significantly.

Below is the comparison of the vulnerable and patched versions of deps/streamsearch/sbmh.js showing how the shift distances are calculated:

// Vulnerable Implementation (v3.1.0 - v3.2.0)
function SBMH (needle) {
  this.maxMatches = Infinity
  this.matches = 0
 
  // BUG: Uint8Array(256) cannot store values >= 256.
  // A needle length of 256 wraps down to 0, neutralizing shift distances.
  this._occ = new Uint8Array(256).fill(needleLength)
  this._lookbehind_size = 0
  this._needle = needle
}
// Patched Implementation (v3.2.1)
function SBMH (needle) {
  this.maxMatches = Infinity
  this.matches = 0
 
  // FIX: Widening the backing store to Uint16Array prevents the wrap-around.
  // This array can safely hold needle lengths up to 65,535.
  this._occ = new Uint16Array(256).fill(needleLength)
  this._lookbehind_size = 0
  this._needle = needle
}

While this fix successfully resolves the integer overflow for needle sizes below 65,536 bytes, a boundary constraint assessment reveals that theoretical overflows could still exist if an application permitted needles longer than 65,535 bytes. However, HTTP header length limitations and typical buffer limits in Node.js platforms restrict practical boundary lengths well below this threshold. Thus, the patch is highly effective for realistic operational environments.

Attack Methodology and Exploitation

Exploiting this flaw is simple and requires no specialized privileges, authentication, or sequence of API calls. The attacker needs only to send a single HTTP POST request containing a crafted multipart boundary parameter in the Content-Type header. The target application must be configured to process incoming form data using an affected version of the @fastify/busboy module.

To construct the payload, the attacker crafts a string of exactly 252 characters to act as the boundary parameter. When the server processes this header, it adds standard multipart syntax wrappers (specifically prepending -- characters), bringing the internal search needle size to exactly 256 bytes. When the client begins streaming the request body, the parsing engine triggers the matching logic against the input data.

As shown in the flow diagram, the calculation of a zero shift distance blocks all processing progress. The application stays trapped inside the execution loop, consuming 100% of the allocated CPU core resources and remaining unresponsive to any network traffic.

Security Impact Assessment

The primary security consequence of CVE-2026-19484 is complete application-level Denial of Service (DoS). Since Node.js handles incoming I/O operations and database queries on a single-threaded event loop, stalling this thread prevents any other asynchronous callbacks or requests from executing. As a result, a single malicious HTTP request can compromise the availability of an entire application process.

If the application is deployed behind a load balancer without health check-based autoscaling, a sustained attack consisting of few requests can disable the entire application tier. If the server is configured to automatically restart upon crash, this flaw poses an even greater disruption, as it does not trigger an actual process crash (segmentation fault or unhandled exception). Instead, the process remains running indefinitely in a hung state, rendering passive process monitoring tools ineffective.

This vulnerability is tracked with a CVSS v3.1 score of 7.5, classifying it as High severity. The low attack complexity, combined with the lack of authentication or user interaction requirements, elevates the threat profile for high-traffic endpoints that expose file-upload functionalities to the public internet.

Remediation and Defense in Depth

The primary mitigation action is to upgrade @fastify/busboy to version 3.2.1 or higher. For applications using umbrella frameworks or dependency injectors that bundle busboy transitively, dependency resolution overrides should be declared within the package lockfiles (e.g., using NPM overrides or Yarn resolutions) to force the usage of the patched version.

If immediate dependency upgrades are not feasible, network-level mitigations should be implemented. According to RFC 2046 Section 5.1.1, multipart boundaries should not exceed 70 characters in length. Security teams can configure Web Application Firewalls (WAFs) or reverse proxies to inspect the Content-Type header and drop any request containing a boundary parameter length that exceeds this standard threshold.

# Example Nginx configuration block to inspect boundary length
if ($http_content_type ~* "boundary=[a-zA-Z0-9'\(\)\+,\-\./:=\?]{71,}") {
    return 400 "Bad Request: Boundary length exceeds RFC 2046 limits.";
}

Additionally, implementing application-level timeouts and monitoring CPU utilization anomalies can help identify and isolate stalled processes. However, these runtime defensive measures should complement, rather than substitute, the library update to 3.2.1.

Official Patches

FastifyFix Commit in sbmh.js

Fix Analysis (1)

Technical Appendix

CVSS Score
7.5/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Probability
0.61%
Top 52% most exploited

Affected Systems

@fastify/busboy

Affected Versions Detail

Product
Affected Versions
Fixed Version
@fastify/busboy
Fastify
>= 3.1.0, <= 3.2.03.2.1
AttributeDetail
CWE IDCWE-835
Attack VectorNetwork
CVSS Score7.5 (High)
EPSS Score0.00615 (47.57th percentile)
ImpactComplete Application Denial of Service
Exploit StatusProof of Concept available
KEV StatusNot listed

MITRE ATT&CK Mapping

T1499.004Endpoint Denial of Service: Application Exhaustion Flood
Impact
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')

The program enters an infinite loop, or a loop with an exit condition that cannot be met, leading to excessive resource consumption.

Known Exploits & Detection

GitHub Security AdvisoryExploit replication utilizing a 252-byte multipart boundary block.

Vulnerability Timeline

Official fix committed by Matteo Collina
2026-08-12
CVE-2026-19484 published to databases
2026-08-13
GitHub Security Advisory GHSA-xjh9-v7x6-24jw released
2026-08-13

References & Sources

  • [1]https://nvd.nist.gov/vuln/detail/CVE-2026-19484
  • [2]https://github.com/fastify/busboy/security/advisories/GHSA-xjh9-v7x6-24jw
  • [3]https://github.com/fastify/busboy/commit/632a237e7fb6b3b7a30e0de8fab2ee72ca5bf722
  • [4]https://cna.openjsf.org/security-advisories.html
  • [5]https://github.com/fastify/busboy/releases/tag/v3.2.1

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•18 minutes ago•GHSA-CJCG-CXMH-9WCR
7.5

GHSA-cjcg-cxmh-9wcr: Unbounded Memory Allocation via HTTP/2 Bomb in praxis-proxy

A critical vulnerability exists in the praxis-proxy library where the omission of default limits on HTTP/2 server options allows remote attackers to trigger a Denial of Service (DoS) using an HPACK compression bomb and flow-control window stalls. This vulnerability is cataloged as GHSA-cjcg-cxmh-9wcr.

Amit Schendel
Amit Schendel
0 views•7 min read
•about 1 hour ago•GHSA-MWM8-39RW-8826
8.1

GHSA-MWM8-39RW-8826: Use-After-Free Vulnerability in Ruby sqlite3 Gem native extension

A Use-After-Free (UAF) vulnerability exists in the sqlite3-ruby native C extension when marshaling arguments for user-defined SQLite aggregate functions with multiple arguments. Due to temporary heap-allocated argument arrays not being registered with the Ruby Garbage Collector, active objects can be prematurely reclaimed, resulting in memory corruption or process-level crashes.

Alon Barad
Alon Barad
2 views•7 min read
•about 3 hours ago•CVE-2026-19481
7.5

CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy

A critical remote, unauthenticated Denial of Service (DoS) vulnerability in @fastify/busboy (<= 3.2.0) allows attackers to crash the Node.js process. By submitting a crafted multipart/form-data request with a header key matching an inherited property of Object.prototype (like __proto__ or constructor), the internal HeaderParser triggers a synchronous TypeError.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 4 hours ago•GHSA-P23F-CM6Q-2QP8
8.6

GHSA-P23F-CM6Q-2QP8: Workspace Boundary Bypass and Arbitrary File Leak in SiYuan MCP

SiYuan is an open-source personal knowledge management system. Its Model Context Protocol (MCP) implementation within the asset.upload tool contains a path-traversal and workspace boundary bypass flaw. This allows remote AI models—acting on behalf of attackers via malicious prompts or documents—to import and read sensitive host-system files, such as private keys and system configurations, through absolute path inputs.

Alon Barad
Alon Barad
5 views•6 min read
•about 5 hours ago•GHSA-X8GV-G2G3-65FJ
8.2

CVE-2026-82234: Server-Side Request Forgery via DNS-Rebinding TOCTOU in SiYuan Kernel

An Server-Side Request Forgery (SSRF) vulnerability via DNS-Rebinding Time-of-Check to Time-of-Use (TOCTOU) has been discovered in SiYuan (思源笔记), an open-source personal knowledge management system. The flaw exists within the AI Agent tools http_request (util.HTTPRequest) and web_fetch (util.WebFetch) of the SiYuan Kernel, allowing unauthenticated remote attackers to bypass SSRF validation and access private internal services or cloud metadata endpoints.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 6 hours ago•CVE-2026-104861
7.5

CVE-2026-104861: Quadratic-time Regular Expression Denial of Service in probe-image-size SVG Parser

An uncontrolled resource consumption vulnerability (CWE-1333 / CWE-400) exists in probe-image-size versions prior to 7.4.0. The SVG parser utilizes an unanchored, inefficient regular expression to find the SVG root tag, leading to catastrophic backtracking when handling malformed payloads. This blocks the single-threaded Node.js event loop, resulting in a complete denial of service.

Amit Schendel
Amit Schendel
5 views•9 min read