THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18549 (HIGH 7.5) — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the cli

[NVD] CVE-2026-18549 (HIGH 7.5) — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the cli

mednvdPublished 2026-08-15

CVE-2026-18549 CVSS: 7.5 HIGH Published: 2026-08-15T14:17:07.590

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the client then aborts the connection before sending the term

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18549