StackRadar

CVE-2026-19484

High

Advisory

Published 2 Oct 2026In the index since 3 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 18,026 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary

Carried by container images the latest versions of 11 of 18,026 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
@fastify/busboynpm3.1.1, 3.2.03.2.111
OSV records
GHSA-xjh9-v7x6-24jw

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
@fastify/busboy@3.1.1
3.2.1

Open the chart page →

8,704
docmosthelmforgeVerified publisher1.4.01 of 4See more

docmost helmforge 1.4.0

1 of the 4 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
docmost/docmost:0.96.0b56947fcfd08
@fastify/busboy@3.1.1
3.2.1

Open the chart page →

4,620
openhabhelmforgeVerified publisher1.2.01 of 1See more

openhab helmforge 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
openhab/openhab:5.2.1bfd4a60e90da
@fastify/busboy@3.1.1
3.2.1

Open the chart page →

4,417
dawarichcogitriVerified publisher2.9.21 of 3See more

dawarich cogitri 2.9.2

1 of the 3 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.2e58334ca5697
@fastify/busboy@3.1.1
3.2.1

Open the chart page →

6,974
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
supabase/storage-api:v1.60.4c8eb9858eafe
@fastify/busboy@3.1.1
3.2.1

Open the chart page →

21,495
dawarichhelmforgeVerified publisher1.0.21 of 4See more

dawarich helmforge 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
freikin/dawarich:1.15.2e58334ca5697
@fastify/busboy@3.1.1
3.2.1

Open the chart page →

12,097
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
infisical/infisical:latest3365445909be
@fastify/busboy@3.1.1
3.2.1

Open the chart page →

3,361
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
@fastify/busboy@3.2.0
3.2.1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
@fastify/busboy@3.2.0
3.2.1

Open the chart page →

3,882
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
@fastify/busboy@3.2.0
3.2.1

Open the chart page →

2,859
infisicalsinextraVerified publisher0.6.11 of 1See more

infisical sinextra 0.6.1

1 of the 1 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.166b911e3938ac
@fastify/busboy@3.1.1
3.2.1

Open the chart page →

3,361
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-19484.

Container imageDigestPackageFixed in
supabase/storage-api:latest5fea789899d4
@fastify/busboy@3.1.1
3.2.1

Open the chart page →

10,655

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
freikin/dawarich:1.15.2e58334ca5697
@fastify/busboy@3.1.1
3.2.1
2
docmost/docmost:0.96.0b56947fcfd08
@fastify/busboy@3.1.1
3.2.1
1
haohanyang/compass-web:0.5.054f2112602ee
@fastify/busboy@3.2.0
3.2.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
@fastify/busboy@3.1.1
3.2.1
1
infisical/infisical:latest3365445909be
@fastify/busboy@3.1.1
3.2.1
1
infisical/infisical:v0.165.166b911e3938ac
@fastify/busboy@3.1.1
3.2.1
1
openhab/openhab:5.2.1bfd4a60e90da
@fastify/busboy@3.1.1
3.2.1
1
supabase/storage-api:latest5fea789899d4
@fastify/busboy@3.1.1
3.2.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
@fastify/busboy@3.1.1
3.2.1
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
@fastify/busboy@3.2.0
3.2.1
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
@fastify/busboy@3.2.0
3.2.1
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.