fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
🔗 CVE IDs covered (1)
📋 Description
Impact
fastify crashes with an uncaught ERR_HTTP2_INVALID_CONNECTION_HEADERS exception when a route that registers a response trailer via reply.trailer() is served over HTTP/2. Fastify unconditionally adds the Transfer-Encoding: chunked header when a trailer is set, which is forbidden on HTTP/2, so Node.js throws while serializing the response headers. The exception is not caught and becomes an uncaughtException, terminating the Node.js process.
One unauthenticated HTTP/2 request to any route that uses trailers is enough to crash the server, dropping all in-flight requests, and the request can be repeated to keep the process down. Applications are affected only when HTTP/2 is enabled (http2: true) and at least one route registers a trailer. HTTP/1.x responses are not affected.
Patches
Upgrade to fastify 5.12.5 or later.
Workarounds
Avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until upgrading.
🎯 Affected products1
- npm/fastify:< 5.12.5
🔗 References (7)
- https://github.com/fastify/fastify/security/advisories/GHSA-4mh8-r7rc-xpvc
- https://nvd.nist.gov/vuln/detail/CVE-2026-92081
- https://github.com/fastify/fastify/issues/6574
- https://github.com/fastify/fastify/commit/ad06a4c3fe8a944a904f38068249b18b8f552e90
- https://cna.openjsf.org/security-advisories.html
- https://github.com/fastify/fastify/releases/tag/v5.12.5
- https://github.com/advisories/GHSA-4mh8-r7rc-xpvc