<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T02:39:14.109991+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352006</id>
    <title>EUVD-2026-352006</title>
    <updated>2026-10-06T02:39:14.166177+00:00</updated>
    <content>EUVD-2026-352006</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-19481</id>
    <title>fkie_cve-2026-19481</title>
    <updated>2026-10-06T02:39:14.166218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves to a truthy non-array value and triggers a TypeError. In the common pipe integration the failure surfaces as an error event, but in direct write or end usage the exception is thrown synchronously and can terminate the Node.js process, causing an unauthenticated denial of service. The issue is fixed in @fastify/busboy 3.2.1, which creates the header object with a null prototype. Users should upgrade to 3.2.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-19481"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x8mw-p69m-v3mx</id>
    <title>GHSA-x8mw-p69m-v3mx — @fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header</title>
    <updated>2026-10-06T02:39:14.166256+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @fastify/busboy</p>
<p>### Impact</p>
<p>Versions of `@fastify/busboy` from 1.0.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The multipart header parser stores part-header names on a plain JavaScript object, so a part header named `__proto__` or `constructor` resolves to an inherited value that is not an array, and the parser throws `TypeError: this.header[h].push is not a function`. Through the documented `req.pipe(busboy)` integration this surfaces as an `error` event, while direct `write()`/`end()` usage throws synchronously and can terminate the Node.js process if uncaught. The parser runs before application middleware, so any unauthenticated client that can submit multipart/form-data is affected.</p>
<p>### Patches</p>
<p>Fixed in version 3.2.1.</p>
<p>### Workarounds</p>
<p>Attach an `error` listener to the Busboy stream so the parser failure is handled rather than crashing the process, and wrap direct `write()`/`end()` calls in a try/catch. Upgrading to 3.2.1 removes the failure entirely.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x8mw-p69m-v3mx"/>
  </entry>
</feed>
