Repository navigation
chore(deps): update vulnerable [security] - #37
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
from
January 21, 2026 06:10
74ed197 to
8291022
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
2 times, most recently
from
February 2, 2026 23:05
57c0622 to
bbca5fe
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
3 times, most recently
from
February 18, 2026 06:28
b7b9a39 to
0959fa9
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
2 times, most recently
from
March 11, 2026 21:39
b40ad96 to
d7a35e7
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
from
March 25, 2026 21:45
d7a35e7 to
2d86b58
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
from
April 16, 2026 10:48
2d86b58 to
501f089
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
2 times, most recently
from
May 18, 2026 16:02
392faad to
7d76676
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
2 times, most recently
from
June 15, 2026 23:37
bfc3419 to
d239d75
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
2 times, most recently
from
July 25, 2026 00:02
fb34bef to
a1d635b
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
2 times, most recently
from
July 30, 2026 17:35
a2e971d to
908543e
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
from
August 11, 2026 23:38
908543e to
f82c022
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
from
August 26, 2026 15:59
f82c022 to
b5834d7
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
from
September 3, 2026 01:38
b5834d7 to
d0ff549
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
from
September 3, 2026 19:57
d0ff549 to
dd059b0
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
3 times, most recently
from
September 17, 2026 16:58
ccba54f to
f9b22b1
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
2 times, most recently
from
September 20, 2026 17:26
fe48d88 to
a32c141
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
from
October 1, 2026 06:03
a32c141 to
c268396
Compare
renovate
Bot
force-pushed
the
renovate/vulnerable
branch
from
October 5, 2026 13:05
c268396 to
c6bfb39
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.13.4→1.13.65.3.3→5.12.57.4.3→7.5.21@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
CVE-2026-48069 / GHSA-99f4-grh7-6pcq
More information
Details
Impact
An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js
Patches
The following version have fixes for this vulnerability:
Workarounds
There is no workaround.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
@grpc/grpc-js: A malformed request can cause a server crash
CVE-2026-48068 / GHSA-5375-pq7m-f5r2
More information
Details
Impact
An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js.
Patches
The following version have fixes for this vulnerability:
Workarounds
There is no workaround.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
CVE-2026-101915 / GHSA-f596-whhp-79r4
More information
Details
Impact
If an application method handler crashes, the error message is included in the status message sent to the client. This can leak to the client any sensitive data that may be included in the error message. This impacts anyone using
@grpc/grpc-jsto run servers.Patches
This vulnerability is fixed in 1.13.6 and 1.14.5.
Workarounds
This can be avoided by using a top-level error handler in method handlers to strip out sensitive error information.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
CVE-2026-101916 / GHSA-m9gg-hp2v-232j
More information
Details
Impact
When server credentials are created with the
requireClientCertificateoption set tofalse,getAuthContextdoes not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for@grpc/grpc-jsusers who use the result ofgetAuthContextfor authentication.In particular,
@grpc/grpc-js-xdscan both set therequireClientCertificateoption tofalseand use the return value ofgetAuthContextfor RBAC authentication in some configurations.Patches
This vulenrability is fixed in 1.13.6 and 1.14.5.
Workarounds
@grpc/grpc-jsusers usinggetAuthContextthis way can avoid this problem by settingrequireClientCertificatetotrue.@grpc/grpc-js-xdsusers using RBAC can avoid this by setting therequire_client_certificatefield totruein the DownstreamTlsContext in the xDS configuration.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
@grpc/grpc-js: A malformed request can cause a server crash
CVE-2026-48068 / GHSA-5375-pq7m-f5r2
More information
Details
Impact
An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js.
Patches
The following version have fixes for this vulnerability:
Workarounds
There is no workaround.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
CVE-2026-48069 / GHSA-99f4-grh7-6pcq
More information
Details
Impact
An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js
Patches
The following version have fixes for this vulnerability:
Workarounds
There is no workaround.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
CVE-2026-101915 / GHSA-f596-whhp-79r4
More information
Details
Impact
If an application method handler crashes, the error message is included in the status message sent to the client. This can leak to the client any sensitive data that may be included in the error message. This impacts anyone using
@grpc/grpc-jsto run servers.Patches
This vulnerability is fixed in 1.13.6 and 1.14.5.
Workarounds
This can be avoided by using a top-level error handler in method handlers to strip out sensitive error information.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
CVE-2026-101916 / GHSA-m9gg-hp2v-232j
More information
Details
Impact
When server credentials are created with the
requireClientCertificateoption set tofalse,getAuthContextdoes not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for@grpc/grpc-jsusers who use the result ofgetAuthContextfor authentication.In particular,
@grpc/grpc-js-xdscan both set therequireClientCertificateoption tofalseand use the return value ofgetAuthContextfor RBAC authentication in some configurations.Patches
This vulenrability is fixed in 1.13.6 and 1.14.5.
Workarounds
@grpc/grpc-jsusers usinggetAuthContextthis way can avoid this problem by settingrequireClientCertificatetotrue.@grpc/grpc-js-xdsusers using RBAC can avoid this by setting therequire_client_certificatefield totruein the DownstreamTlsContext in the xDS configuration.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Fastify's Content-Type header tab character allows body validation bypass
CVE-2026-25223 / GHSA-jx2c-rxcm-jvmq
More information
Details
Impact
A validation bypass vulnerability exists in Fastify where request body validation schemas specified by Content-Type can be completely circumvented. By appending a tab character (
\t) followed by arbitrary content to the Content-Type header, attackers can bypass body validation while the server still processes the body as the original content type.For example, a request with
Content-Type: application/json\tawill bypass JSON schema validation but still be parsed as JSON.This vulnerability affects all Fastify users who rely on Content-Type-based body validation schemas to enforce data integrity or security constraints. The concrete impact depends on the handler implementation and the level of trust placed in the validated request body, but at the library level, this allows complete bypass of body validation for any handler using Content-Type-discriminated schemas.
This issue is a regression or missed edge case from the fix for a previously reported vulnerability.
Patches
This vulnerability has been patched in Fastify v5.7.2. All users should upgrade to this version or later immediately.
Workarounds
If upgrading is not immediately possible, user can implement a custom
onRequesthook to reject requests containing tab characters in the Content-Type header:Resources
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
CVE-2026-25224 / GHSA-mrq3-vjjr-p77c
More information
Details
Impact
A Denial of Service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applications that return a
ReadableStream(orResponsewith a Web Stream body) viareply.send()are impacted. A slow or non-reading client can trigger unbounded buffering when backpressure is ignored, leading to process crashes or severe degradation.Patches
The issue is fixed in Fastify 5.7.3. Users should upgrade to 5.7.3 or later.
Workarounds
Avoid sending Web Streams from Fastify responses (e.g.,
ReadableStreamorResponsebodies). Use Node.js streams (stream.Readable) or buffered payloads instead until the project can upgrade.References
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
CVE-2026-3635 / GHSA-444r-cwp2-x5xf
More information
Details
Summary
When
trustProxyis configured with a restrictive trust function (e.g., a specific IP liketrustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), therequest.protocolandrequest.hostgetters readX-Forwarded-ProtoandX-Forwarded-Hostheaders from any connection — including connections from untrusted IPs. This allows an attacker connecting directly to Fastify (bypassing the proxy) to spoof both the protocol and host seen by the application.Affected Versions
fastify <= 5.8.2
Impact
Applications using
request.protocolorrequest.hostfor security decisions (HTTPS enforcement, secure cookie flags, CSRF origin checks, URL construction, host-based routing) are affected whentrustProxyis configured with a restrictive trust function.When
trustProxy: true(trust everything), bothhostandprotocoltrust all forwarded headers — this is expected behavior. The vulnerability only manifests with restrictive trust configurations.Severity
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header
CVE-2026-33806 / GHSA-247c-9743-5963
More information
Details
Summary
A validation bypass vulnerability exists in Fastify v5.x where request body validation schemas specified via
schema.body.contentcan be completely circumvented by prepending a single space character (\x20) to theContent-Typeheader. The body is still parsed correctly as JSON (or any other content type), but schema validation is entirely skipped.This is a regression introduced by commit
f3d2bcb(fix for CVE-2025-32442).Details
The vulnerability is a parser-validator differential between two independent code paths that process the raw
Content-Typeheader differently.Parser path (
lib/content-type.js, line ~67) appliestrimStart()before processing:Validator path (
lib/validation.js, line 272) splits on/[ ;]/before trimming:The
ContentTypeclass appliestrimStart()before processing, so the parser correctly identifiesapplication/jsonand parses the body. However,getEssenceMediaTypesplits on/[ ;]/before trimming, so the leading space becomes a split point, producing an empty string. The validator looks up a schema for content-type"", finds nothing, and skips validation entirely.Regression source: Commit
f3d2bcb(April 18, 2025) changed the split delimiter from';'to/[ ;]/to fix CVE-2025-32442. The old code (header.split(';', 1)[0].trim()) was not vulnerable to this vector because.trim()would correctly handle the leading space. The new regex-based split introduced the regression.PoC
Output:
Impact
Any Fastify application that relies on
schema.body.content(per-content-type body validation) to enforce data integrity or security constraints is affected. An attacker can bypass all body validation by adding a single space before the Content-Type value. The attack requires no authentication and has zero complexity — it is a single-character modification to an HTTP header.This vulnerability is distinct from all previously patched content-type bypasses:
Recommended fix — add
trimStart()before the split ingetEssenceMediaType:Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
CVE-2026-18504 / GHSA-w2qp-rph6-63g4
More information
Details
Impact
fastifybefore 5.12.1, when a route uses a root-level primitive body schema (for example an integer with a minimum and maximum) and the default type coercion, validates the coerced value but exposes the original, uncoerced value to the route handler. For example, a JSON body"10"is coerced to the number10and passes an integer 1 to 10 schema, butrequest.bodystays the string"10". An application that trusts the validated type is handed a value that did not satisfy the schema, which can bypass limits the application enforces on that typed value. Object and array body schemas are not affected, they coerce their members in place.Patches
Upgrade to
fastify5.12.1.Workarounds
Until you can upgrade, avoid relying on the validated type of a root primitive body. Wrap the value in an object schema (object properties are coerced in place), for example accept
{ "value": 10 }and readrequest.body.value, or re-check the type in the handler.Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
CVE-2026-76169 / GHSA-p68q-wchp-6fh7
More information
Details
Impact
Fastify routes a malformed URL under one plugin prefix to the custom not-found handler of a different sibling plugin, invoking the handler registered last and skipping the
preHandlerdeclared in itssetNotFoundHandler(). When the request method has no route in the main router, a malformed request target reaches Fastify's internal not-found router before URL decoding and is dispatched through a single shared handler pointer, regardless of prefix and without the normal request lifecycle. An unauthenticated request to a public prefix can therefore reach an authentication-protected not-found handler registered under a different prefix and receive its full response, breaking prefix encapsulation and bypassing the authentication hook. Applications whose private or tenant fallbacks return protected data from a not-found handler are affected.Patches
Patched in fastify 5.12.2. Malformed URLs are now routed through the configured
onBadUrlandonMaxParamLengthhandlers so they fail closed before any application not-found handler runs, and the shared not-found handler pointer has been removed.Workarounds
Reject malformed request targets before they reach the application, for example at an upstream proxy or gateway, and do not rely on a not-found handler to serve protected data. A global
onRequestauthentication hook does not mitigate this, because the malformed-URL path skips it.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to request body replacement via an async validation result collision
CVE-2026-84504 / GHSA-667r-xxjv-c9mm
More information
Details
Impact
Fastify runs a route's validator and, for a result shaped like
{ value, error }, unwraps it: anerrorbecomes a validation failure andvaluereplaces the request part. This convention is intended for synchronous custom compilers (for example Joi). A JSON Schema$asyncvalidator, however, resolves with the validated data itself, so Fastify applied the same unwrapping to it. If a request part validated by an$asyncschema contains avalueproperty, Fastify replaced the whole request part with that nested value before the handler ran, so avalueorerrorproperty in the payload was attacker-controlled. An application that dispatches operations from the validated request body could then act on data that never satisfied the route schema, leading to unauthorized state changes or disclosure. Reaching the vulnerable path requires the route to use an$asyncrequest schema.Patches
Fastify no longer treats an asynchronous validation result as a
{ value, error }wrapper: an async validator's resolved value is used only to determine pass or fail, and it can no longer replace the request part or inject an error. The synchronous custom-compiler contract is unchanged. Patched in fastify5.12.2and6.0.0.Workarounds
If upgrading is not immediately possible, avoid
$asyncrequest schemas, or perform the security-sensitive check in anonRequestorpreHandlerhook rather than relying on the schema-validated request part. Custom async validator compilers should signal failure by throwing (rejecting) rather than returning an{ error }object.Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to request validation bypass via skipped boolean false schemas
CVE-2026-84469 / GHSA-hwr6-493r-vm6h
More information
Details
Impact
Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean
falseas a valid schema that rejects every instance, but becausefalseis falsy, a route that setbody,querystring,params, orheaderstofalsehad that part left uncompiled: no validator was attached and the request reached the handler. An application that usedfalseas a deny-all schema to make a route unreachable was therefore fully bypassed, and an unauthenticated remote client could reach the handler with any input. The same applied to the documentedqueryalias forquerystring. This is a complete bypass rather than a weak-schema issue, sincefalseis the strongest JSON Schema assertion and must always fail.Patches
Request-part schemas are now selected by an explicit presence check rather than truthiness, so a boolean
false(ortrue) schema is compiled and enforced, including through thequeryalias. Patched in fastify5.12.2. The fix is also included in the6.0.0release.Workarounds
If upgrading is not immediately possible, express a deny-all request schema with an always-failing object schema instead of the boolean
false(for example{ "not": {} }), or reject the request in anonRequesthook.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to header validation bypass via incomplete schema case normalization
CVE-2026-84428 / GHSA-9q9j-q6p8-xq58
More information
Details
Impact
Fastify lowercases header-schema property names before compiling the schema, because Node.js stores request header names in lowercase. That normalization was incomplete: it lowercased only top-level
propertieskeys and the rootrequiredarray, and did not lowercase the JSON Schema Draft 7dependencieskeyword (its trigger keys and dependent property names) or names in nested subschemas. As a result, a header schema that usesdependenciesto require one header when another is present (for exampleX-AdminrequiringX-Admin-Token) never matches the lowercased request headers, so the dependency assertion is silently skipped. An unauthenticated remote client can send the header that activates a privileged path while omitting the header the dependency was meant to require, bypassing a schema-enforced security control. The header schema is idiomatic, valid JSON Schema Draft 7, and no custom validator, malformed request, or misconfiguration is required.Patches
Header-schema names are now normalized across all schema positions (
properties,required,dependencies,dependentRequired,dependentSchemas, and nested subschemas). Patched in fastify5.12.2. The fix is also included in the6.0.0release. Header schemas referenced through an external shared$ref(registered withaddSchema) are not reached by this normalization and now emit anFSTSEC002startup warning; inline the header schema to keep case-insensitive assertions in effect.Workarounds
If upgrading is not immediately possible, write header-schema names in lowercase so the
dependenciesand other case-sensitive assertions match Node's lowercased request headers, or enforce the cross-header requirement in anonRequestorpreValidationhook instead of the schema.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
CVE-2026-92081 / GHSA-4mh8-r7rc-xpvc
More information
Details
Impact
fastifycrashes with an uncaughtERR_HTTP2_INVALID_CONNECTION_HEADERSexception when a route that registers a response trailer viareply.trailer()is served over HTTP/2. Fastify unconditionally adds theTransfer-Encoding: chunkedheader when a trailer is set, which is forbidden on HTTP/2, so Node.js throws while serializing the response headers. The exception is not caught and becomes an uncaughtException, terminating the Node.js process.One unauthenticated HTTP/2 request to any route that uses trailers is enough to crash the server, dropping all in-flight requests, and the request can be repeated to keep the process down. Applications are affected only when HTTP/2 is enabled (
http2: true) and at least one route registers a trailer. HTTP/1.x responses are not affected.Patches
Upgrade to
fastify5.12.5or later.Workarounds
Avoid registering response trailers with
reply.trailer()on routes served over HTTP/2 until upgrading.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Fastify's Content-Type header tab character allows body validation bypass
CVE-2026-25223 / GHSA-jx2c-rxcm-jvmq
More information
Details
Impact
A validation bypass vulnerability exists in Fastify where request body validation schemas specified by Content-Type can be completely circumvented. By appending a tab character (
\t) followed by arbitrary content to the Content-Type header, attackers can bypass body validation while the server still processes the body as the original content type.For example, a request with
Content-Type: application/json\tawill bypass JSON schema validation but still be parsed as JSON.This vulnerability affects all Fastify users who rely on Content-Type-based body validation schemas to enforce data integrity or security constraints. The concrete impact depends on the handler implementation and the level of trust placed in the validated request body, but at the library level, this allows complete bypass of body validation for any handler using Content-Type-discriminated schemas.
This issue is a regression or missed edge case from the fix for a previously reported vulnerability.
Patches
This vulnerability has been patched in Fastify v5.7.2. All users should upgrade to this version or later immediately.
Workarounds
If upgrading is not immediately possible, user can implement a custom
onRequesthook to reject requests containing tab characters in the Content-Type header:Resources
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
CVE-2026-25224 / GHSA-mrq3-vjjr-p77c
More information
Details
Impact
A Denial of Service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applications that return a
ReadableStream(orResponsewith a Web Stream body) viareply.send()are impacted. A slow or non-reading client can trigger unbounded buffering when backpressure is ignored, leading to process crashes or severe degradation.Patches
The issue is fixed in Fastify 5.7.3. Users should upgrade to 5.7.3 or later.
Workarounds
Avoid sending Web Streams from Fastify responses (e.g.,
ReadableStreamorResponsebodies). Use Node.js streams (stream.Readable) or buffered payloads instead until the project can upgrade.References
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
fastify: request.protocol and request.host Spoofable via