Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

fastify — Vulnerabilities & Security Advisories 35

Browse all 35 CVE security advisories affecting fastify. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Fastify is a high-performance web framework for Node.js, primarily designed to facilitate the rapid development of backend APIs and microservices. Its architecture emphasizes low overhead and high throughput, making it a popular choice for scalable server-side applications. Security audits reveal a history of twenty-eight recorded Common Vulnerabilities and Exposures (CVEs), predominantly involving prototype pollution, denial-of-service conditions, and improper input validation. These flaws often stem from complex middleware interactions or inadequate sanitization of user-supplied data, potentially leading to remote code execution or privilege escalation in misconfigured environments. While the framework itself enforces strict schema validation by default, vulnerabilities frequently arise from developer oversight in plugin integration or dependency management. Major incidents have highlighted risks related to unhandled exceptions and insecure default configurations, necessitating rigorous code reviews and timely patching to maintain application integrity in production deployments.

CVE ID Title CVSS Severity Published
CVE-2026-92081 fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses — fastify CWE-248 5.9 Medium 2026-09-16
CVE-2026-84428 fastify vulnerable to header validation bypass via incomplete schema case normalization — fastify CWE-178 7.5 High 2026-09-04
CVE-2026-84469 fastify vulnerable to request validation bypass via skipped boolean false schemas — fastify CWE-20 7.5 High 2026-09-04
CVE-2026-76169 fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers — fastify CWE-288 7.5 High 2026-09-04
CVE-2026-84504 fastify vulnerable to request body replacement via an async validation result collision — fastify CWE-20 8.1 High 2026-09-04
CVE-2026-16732 fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count — fastify CWE-348 6.1 Medium 2026-08-18
CVE-2026-18504 fastify vulnerable to schema validation bypass via root primitive coercion mismatch — fastify CWE-20 5.4 Medium 2026-08-18
CVE-2026-33807 @fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes — @fastify/express CWE-436 9.1 Critical 2026-04-15
CVE-2026-33808 @fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons) — @fastify/express CWE-436 9.1 - 2026-04-15
CVE-2026-33806 fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header — fastify CWE-1287 7.5 High 2026-04-15
CVE-2026-3635 Fastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function — fastify CWE-348 6.1 Medium 2026-03-23
CVE-2026-3419 Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation — fastify CWE-185 5.3 Medium 2026-03-06
CVE-2026-25223 Fastify's Content-Type header tab character allows body validation bypass — fastify CWE-436 7.5 High 2026-02-03
CVE-2026-25224 Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream — fastify CWE-770 3.7 Low 2026-02-03
CVE-2026-22037 @fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding) — fastify-express CWE-177 8.4 High 2026-01-19
CVE-2026-22031 Fastify Middie Middleware Path Bypass — middie CWE-177 8.4 High 2026-01-19
CVE-2025-66415 fastify-reply-from bypass of reply forwarding — fastify-reply-from CWE-441 6.5AI Medium AI 2025-12-01
CVE-2025-32442 Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass — fastify CWE-1287 7.5 High 2025-04-18
CVE-2025-24033 @fastify/multipart vulnerable to unlimited consumption of resources — fastify-multipart CWE-770 7.5 High 2025-01-23
CVE-2024-35220 @fastify/session reuses destroyed session cookie — session CWE-613 7.4 High 2024-05-21
CVE-2024-31999 @fastify/secure-session: Reuse of destroyed secure session cookie — fastify-secure-session CWE-613 7.4 High 2024-04-10
CVE-2024-22207 Default swagger-ui configuration exposes all files in the module — fastify-swagger-ui CWE-1188 5.3 Medium 2024-01-15
CVE-2023-51701 @fastify-reply-from JSON Content-Type parsing confusion — fastify-reply-from CWE-444 5.3 Medium 2024-01-08
CVE-2023-29020 Cross site request forgery token fixation in fastify-passport — fastify-passport CWE-384 6.5 Medium 2023-04-21
CVE-2023-29019 Session fixation in fastify-passport — fastify-passport CWE-384 8.1 High 2023-04-21
CVE-2023-27495 Bypass of CSRF protection in the presence of predictable userInfo in @fastify/csrf-protection — csrf-protection CWE-352 5.3 Medium 2023-04-20
CVE-2023-25576 @fastify/multipart vulnerable to DoS due to unlimited number of parts — fastify-multipart CWE-770 7.5 High 2023-02-14
CVE-2022-41919 Fastify vulnerable to Cross-Site Request Forgery (CSRF) attack via incorrect content type — fastify CWE-352 4.2 Medium 2022-11-22
CVE-2022-39386 fastify-websocket vulnerable to uncaught exception via crash on malformed packet — fastify-websocket CWE-248 7.5 High 2022-11-08
CVE-2022-39288 Denial of service in Fastify via Content-Type header — fastify CWE-754 7.5 High 2022-10-10

This page lists every published CVE security advisory associated with fastify. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.