Junglewise Threat Intelligence

CVE-2026-74866: @fastify/busboy CRLF injection in multipart headers

CVE-2026-74866 · Severity: medium · CVSS 5.8 · Published 2026-08-21

Vendors: Fastify.

Executive brief

@fastify/busboy is a Node.js library that parses multipart form data uploads. The library fails to strip bare carriage return and line feed characters from filenames and field names, allowing attackers to inject these control characters into downstream systems. An attacker uploading a file with embedded CR/LF characters in the filename could pollute saved filenames, forge log entries, or inject headers into backend systems that process the data.

Technical details

The vulnerability is a CRLF injection (CWE-93) in the multipart part-header parser. The parser treats only the two-byte \r\n sequence as a line terminator, so a lone CR or LF character embedded within a header value is passed verbatim to the application in the filename or field name delivered via the file and field events. An attacker can craft a multipart upload with a filename or field name containing bare CR or LF bytes to inject control characters. No authentication or special privileges are required; the attack is purely network-based. Affected versions are @fastify/busboy 3.2.1 and earlier. Version 3.2.2 fixes the issue by rejecting any header line that still contains bare CR or LF characters.

Affected products

  • fastify @fastify/busboy < 3.2.2

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: patched: version 3.2.2

References

Related threats