THREAT OPS › Threat News › [NVD] CVE-2026-18549 (HIGH 7.5) — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the cli
[NVD] CVE-2026-18549 (HIGH 7.5) — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the cli
CVE-2026-18549 CVSS: 7.5 HIGH Published: 2026-08-15T14:17:07.590
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the client then aborts the connection before sending the term
Indicators of compromise
- CVE-2026-18549cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18549