Fastify

Fastify

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 16.09.2026 08:52:49
  • Zuletzt bearbeitet 16.09.2026 19:40:00

fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fastify unconditionally sets the Transfer-Encoding: chunked header, whic...

  • EPSS 0.28%
  • Veröffentlicht 04.09.2026 10:24:27
  • Zuletzt bearbeitet 15.09.2026 19:54:32

fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level ...

  • EPSS 0.3%
  • Veröffentlicht 04.09.2026 09:59:36
  • Zuletzt bearbeitet 15.09.2026 20:06:50

fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's ...

  • EPSS 0.53%
  • Veröffentlicht 04.09.2026 09:51:03
  • Zuletzt bearbeitet 15.09.2026 20:07:46

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-fo...

  • EPSS 0.39%
  • Veröffentlicht 04.09.2026 09:40:18
  • Zuletzt bearbeitet 15.09.2026 20:05:15

fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fasti...

  • EPSS 0.14%
  • Veröffentlicht 18.08.2026 20:30:22
  • Zuletzt bearbeitet 02.09.2026 14:39:20

fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host, protocol, hostname, ip, and ips values, checking the connecting address. That...

  • EPSS 0.31%
  • Veröffentlicht 18.08.2026 20:19:12
  • Zuletzt bearbeitet 02.09.2026 14:30:22

fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a request body schema targets a root primitive value. When the schema validates a top-level primitive such...

  • EPSS 0.41%
  • Veröffentlicht 15.04.2026 00:14:02
  • Zuletzt bearbeitet 15.07.2026 02:20:15

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. ...

  • EPSS 0.12%
  • Veröffentlicht 23.03.2026 13:53:00
  • Zuletzt bearbeitet 16.04.2026 17:46:58

Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request.protocol and request.host getters read X-Forwarded-Proto and X-Forward...

  • EPSS 0.35%
  • Veröffentlicht 06.03.2026 17:50:58
  • Zuletzt bearbeitet 18.03.2026 19:11:46

Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in violation of RFC 9110 §8.3.1(https://httpwg.org/specs/rfc9110.html#field.content-type). For example, a request sent with Content-T...