Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

fastify — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in fastify, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities for the open-source web framework fastify, focusing on security weaknesses within the node.js ecosystem. It collects reported issues such as denial-of-service flaws, input validation errors, and dependency-related risks, covering advisories from 2019 through the present day. Readers can use this hub to track the vendor's published security advisories, understand the specific weakness classes affecting the product, and review the complete vulnerability history. The collection includes both critical and moderate severity bugs, providing a centralized reference for developers auditing fastify applications. Each entry links to detailed technical descriptions, affected version ranges, and recommended remediation steps, enabling teams to prioritize patching based on potential impact. This resource serves as a practical tool for assessing exposure and maintaining compliance in environments where fastify powers backend services.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-92081 fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses CWE-248 5.9 Medium 2026-09-16
CVE-2026-84428 fastify vulnerable to header validation bypass via incomplete schema case normalization CWE-178 7.5 High 2026-09-04
CVE-2026-84469 fastify vulnerable to request validation bypass via skipped boolean false schemas CWE-20 7.5 High 2026-09-04
CVE-2026-76169 fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers CWE-288 7.5 High 2026-09-04
CVE-2026-84504 fastify vulnerable to request body replacement via an async validation result collision CWE-20 8.1 High 2026-09-04
CVE-2026-16732 fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count CWE-348 6.1 Medium 2026-08-18
CVE-2026-18504 fastify vulnerable to schema validation bypass via root primitive coercion mismatch CWE-20 5.4 Medium 2026-08-18
CVE-2026-33806 fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header CWE-1287 7.5 High 2026-04-15
CVE-2026-3635 Fastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function CWE-348 6.1 Medium 2026-03-23
CVE-2026-3419 Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation CWE-185 5.3 Medium 2026-03-06
CVE-2026-25223 Fastify's Content-Type header tab character allows body validation bypass CWE-436 7.5 High 2026-02-03
CVE-2026-25224 Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream CWE-770 3.7 Low 2026-02-03
CVE-2025-32442 Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass CWE-1287 7.5 High 2025-04-18
CVE-2022-41919 Fastify vulnerable to Cross-Site Request Forgery (CSRF) attack via incorrect content type CWE-352 4.2 Medium 2022-11-22
CVE-2022-39288 Denial of service in Fastify via Content-Type header CWE-754 7.5 High 2022-10-10
CVE-2020-8192 Fastify 资源管理错误漏洞 CWE-400 7.5 - 2020-07-30

All 16 known CVE vulnerabilities affecting fastify with full Chinese analysis, references, and POCs where available.