CVE-2026-92081
- EPSS 0.4%
- Veröffentlicht 16.09.2026 08:52:49
- Zuletzt bearbeitet 16.09.2026 19:40:00
fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fastify unconditionally sets the Transfer-Encoding: chunked header, whic...
CVE-2026-84428
- EPSS 0.28%
- Veröffentlicht 04.09.2026 10:24:27
- Zuletzt bearbeitet 15.09.2026 19:54:32
fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level ...
CVE-2026-84469
- EPSS 0.3%
- Veröffentlicht 04.09.2026 09:59:36
- Zuletzt bearbeitet 15.09.2026 20:06:50
fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's ...
CVE-2026-76169
- EPSS 0.53%
- Veröffentlicht 04.09.2026 09:51:03
- Zuletzt bearbeitet 15.09.2026 20:07:46
fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-fo...
CVE-2026-84504
- EPSS 0.39%
- Veröffentlicht 04.09.2026 09:40:18
- Zuletzt bearbeitet 15.09.2026 20:05:15
fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fasti...
CVE-2026-16732
- EPSS 0.14%
- Veröffentlicht 18.08.2026 20:30:22
- Zuletzt bearbeitet 02.09.2026 14:39:20
fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host, protocol, hostname, ip, and ips values, checking the connecting address. That...
CVE-2026-18504
- EPSS 0.31%
- Veröffentlicht 18.08.2026 20:19:12
- Zuletzt bearbeitet 02.09.2026 14:30:22
fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a request body schema targets a root primitive value. When the schema validates a top-level primitive such...
CVE-2026-33806
- EPSS 0.41%
- Veröffentlicht 15.04.2026 00:14:02
- Zuletzt bearbeitet 15.07.2026 02:20:15
Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. ...
CVE-2026-3635
- EPSS 0.12%
- Veröffentlicht 23.03.2026 13:53:00
- Zuletzt bearbeitet 16.04.2026 17:46:58
Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request.protocol and request.host getters read X-Forwarded-Proto and X-Forward...
CVE-2026-3419
- EPSS 0.35%
- Veröffentlicht 06.03.2026 17:50:58
- Zuletzt bearbeitet 18.03.2026 19:11:46
Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in violation of RFC 9110 §8.3.1(https://httpwg.org/specs/rfc9110.html#field.content-type). For example, a request sent with Content-T...