Skip to main content

Vendor/product archive

fastify / fastify CVEs

Beta · best-effort

10 CVEs tagged to fastify / fastify0 Critical, 5 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2026-33806

Published Apr 15, 2026

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header…

CVSS 7.5 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-3635

Published Mar 23, 2026

Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-3419

Published Mar 6, 2026

Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in violation of RFC 9110 §8.3.1(https://httpwg.org/specs/rfc91…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2026-25224

Published Feb 3, 2026

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a rem…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-25223

Published Feb 3, 2026

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify where request body validation schemas sp…

CVSS 7.5 · High
evidence mentions
12
Buzz score
45.1
Vendor/product tagsBeta · best-effort

CVE-2025-32442

Published Apr 18, 2025

Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, applications that specify different validation strategies for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41919

Published Nov 22, 2022

Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight` checking of `fetch`. `fetch(…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39288

Published Oct 10, 2022

fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of service via malicious use of the Content-Type header. An att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8192

Published Jul 30, 2020

A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with sp…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3711

Published Jun 7, 2018

Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1