fastify
npm17 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting fastifypage 1 of 1
- CVE-2018-3711HIGHCVSS 7.5EG 7.5fixed in 0.38.02018-06-07
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.
- CVE-2020-8192MEDIUMCVSS 6.5EG 6.5fixed in 2.15.12020-07-30
A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.
- CVE-2022-39288HIGHCVSS 7.5EG 8.3fixed in 4.8.12022-10-10
fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of service via malicious use of the Content-Type header. An attacker can send an invalid Content-Type header that can cause…
- CVE-2022-41919MEDIUMCVSS 4.2EG 4.2fixed in 4.10.2 or 3.29.4, by version range2022-11-22
Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight` checking of `fetch`. `fetch()` requests with Content-Type’s essence as "application/x-…
- CVE-2025-32442HIGHCVSS 7.5EG 7.5fixed in 5.8.5, 5.3.2 or 4.29.1, by version range2025-04-18
vulnerable: 4.29.0
Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, applications that specify different validation strategies for different content types have a possibility to bypass validat…
- CVE-2026-16732MEDIUMCVSS 6.1EG 6.1fixed in 5.12.12026-08-18
fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host, protocol, hostname, ip, and ips values, checking the connecting ad…
- CVE-2026-18504MEDIUMCVSS 5.3EG 5.3fixed in 5.12.12026-08-18
fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a request body schema targets a root primitive value. When the schema validates a top-level pri…
- CVE-2026-25223HIGHCVSS 7.5EG 7.5fixed in 5.7.22026-02-03
Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify where request body validation schemas specified by Content-Type can be completely circumvented. By a…
- CVE-2026-25224LOWCVSS 3.7EG 3.7fixed in 5.7.32026-02-03
Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applications that ret…
- CVE-2026-33806HIGHCVSS 7.5EG 7.5fixed in 5.8.5, 5.3.2 or 4.29.1, by version range2026-04-15
vulnerable: 4.29.0
Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation i…
- CVE-2026-3419MEDIUMCVSS 5.3EG 5.3fixed in 5.8.12026-03-06
Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in violation of RFC 9110 §8.3.1(https://httpwg.org/specs/rfc9110.html#field.content-type). For example, a request sent wi…
- CVE-2026-3635MEDIUMCVSS 6.1EG 6.1fixed in 5.8.32026-03-23
Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request.protocol and request.host getters read X-Forwarded-Proto an…
- CVE-2026-76169HIGHCVSS 7.5EG 7.5fixed in 5.12.22026-09-04
fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The inte…
- CVE-2026-84428HIGHCVSS 7.5EG 7.5fixed in 5.12.22026-09-04
fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the …
- CVE-2026-84469HIGHCVSS 7.5EG 7.5fixed in 5.12.22026-09-04
fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to…
- CVE-2026-84504HIGHCVSS 8.1EG 8.1fixed in 5.12.22026-09-04
fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the …
- CVE-2026-92081MEDIUMCVSS 5.9EG 5.9fixed in 5.12.52026-09-16
fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fastify unconditionally sets the Transfer-Encoding: chunked h…
Check whether fastify is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for fastify CVEs against the assets you own.
Book a Demo →