Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

fastify — Vulnerabilities & Security Advisories 35

Browse all 35 CVE security advisories affecting fastify. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Fastify is a high-performance web framework for Node.js, primarily designed to facilitate the rapid development of backend APIs and microservices. Its architecture emphasizes low overhead and high throughput, making it a popular choice for scalable server-side applications. Security audits reveal a history of twenty-eight recorded Common Vulnerabilities and Exposures (CVEs), predominantly involving prototype pollution, denial-of-service conditions, and improper input validation. These flaws often stem from complex middleware interactions or inadequate sanitization of user-supplied data, potentially leading to remote code execution or privilege escalation in misconfigured environments. While the framework itself enforces strict schema validation by default, vulnerabilities frequently arise from developer oversight in plugin integration or dependency management. Major incidents have highlighted risks related to unhandled exceptions and insecure default configurations, necessitating rigorous code reviews and timely patching to maintain application integrity in production deployments.

Found 15 results / 35 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-92081 fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses — fastify CWE-248 5.9 Medium 2026-09-16
CVE-2026-84428 fastify vulnerable to header validation bypass via incomplete schema case normalization — fastify CWE-178 7.5 High 2026-09-04
CVE-2026-84469 fastify vulnerable to request validation bypass via skipped boolean false schemas — fastify CWE-20 7.5 High 2026-09-04
CVE-2026-76169 fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers — fastify CWE-288 7.5 High 2026-09-04
CVE-2026-84504 fastify vulnerable to request body replacement via an async validation result collision — fastify CWE-20 8.1 High 2026-09-04
CVE-2026-16732 fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count — fastify CWE-348 6.1 Medium 2026-08-18
CVE-2026-18504 fastify vulnerable to schema validation bypass via root primitive coercion mismatch — fastify CWE-20 5.4 Medium 2026-08-18
CVE-2026-33806 fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header — fastify CWE-1287 7.5 High 2026-04-15
CVE-2026-3635 Fastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function — fastify CWE-348 6.1 Medium 2026-03-23
CVE-2026-3419 Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation — fastify CWE-185 5.3 Medium 2026-03-06
CVE-2026-25223 Fastify's Content-Type header tab character allows body validation bypass — fastify CWE-436 7.5 High 2026-02-03
CVE-2026-25224 Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream — fastify CWE-770 3.7 Low 2026-02-03
CVE-2025-32442 Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass — fastify CWE-1287 7.5 High 2025-04-18
CVE-2022-41919 Fastify vulnerable to Cross-Site Request Forgery (CSRF) attack via incorrect content type — fastify CWE-352 4.2 Medium 2022-11-22
CVE-2022-39288 Denial of service in Fastify via Content-Type header — fastify CWE-754 7.5 High 2022-10-10

This page lists every published CVE security advisory associated with fastify. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.