THREAT OPS › Threat News › [NVD] CVE-2026-19474 (HIGH 7.5) — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing between multipart parts. The itera
[NVD] CVE-2026-19474 (HIGH 7.5) — @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing between multipart parts. The itera
CVE-2026-19474 CVSS: 7.5 HIGH Published: 2026-08-15T14:17:07.710
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing between multipart parts. The iterator rejection that occurs between parts falls outside
Indicators of compromise
- CVE-2026-19474cve
- CVE-2025-24033cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19474