fastify

5 known vulnerabilities in fastify, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-92081 CVSS 5.9 medium fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via…
  • CVE-2026-84428 CVSS 7.5 high fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema…
  • CVE-2026-84504 CVSS 8.1 high fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom…
  • CVE-2026-84469 CVSS 7.5 high fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines…
  • CVE-2026-76169 CVSS 7.5 high fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a…