Junglewise Threat Intelligence

CVE-2026-19474: @fastify/multipart temporary file leak on disconnect

CVE-2026-19474 · Severity: high · CVSS 7.5 · Published 2026-08-15

Vendors: OpenJS Foundation.

Executive brief

@fastify/multipart is a file upload parser for the Fastify web framework. When a client disconnects during a multipart upload, completed files may be left on disk instead of being cleaned up. An attacker can exploit this by repeatedly uploading files and disconnecting to exhaust disk space, causing the service to become unavailable.

Technical details

The vulnerability is an incomplete-cleanup issue (CWE-459, CWE-770) in the saveRequestFiles() method. When a client completes one multipart part, begins processing a later part, and then disconnects, the async iterator rejection occurs outside the per-file cleanup path, leaving already-completed temporary files on disk. No authentication is required; the attack vector is network-based with low attack complexity. An unauthenticated client can repeatedly trigger this condition to cause linear disk consumption and denial of service. The issue was partially addressed in CVE-2025-24033 but that fix only cleaned up files during the current part. Patch available in version 10.1.1.

Affected products

  • OpenJS Foundation @fastify/multipart 3.0.0 to 10.1.0

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: patched: Fixed in version 10.1.1

References