MEDIUM
@fastify/busboy
CVE published 2026-08-21
CVE-2026-74866
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T09:16:40.890Z and has not been modified since then. The vulnerability affects @fastify/busboy, a multipart form-data parser for Node.js, which does not properly handle lone carriage returns or line feeds in part headers, potentially leading to header injection attacks. Developers should be aware [truncated]