Fixed the fastify.js version mismatch.
Catalog / Backend
Fastify changelog
Node.js web framework that compiles JSON schemas into validation and serialization functions and builds an application from an encapsulated plugin tree.
- Latest
- 5.12.4
- Shipped
- 11 Sep 2026today
- Collected
- 60 releasesback to 2 Jul 2023
- Source
- fastify/fastify
- Project
- fastify.dev
- Advisories
- 14 publishednewest 2026
- Feed
- RSS
Every release of a major line in one list, which is the one view the publisher never writes: 4 to 5. Only the lines whose first release the archive holds are listed, because a partial major would read as the whole of one.
Read today, the first day on record. Collection status
Version history
5.x35 releases
⚠️ Security release Fix for https://github.com/fastify/fastify/security/advisories/GHSA-9q9j-q6p8-xq58 Fix for https://github.com/fastify/fastify/security/advisories/GHSA-hwr6-493r-vm6h Fix for https://github.com/fastify/fastify/security/ad
⚠️ Security release Fix for https://github.com/fastify/fastify/security/advisories/GHSA-w2qp-rph6-63g4 Fix for https://github.com/fastify/fastify/security/advisories/GHSA-3m5p-2c4r-xxw2 What's Changed [Backport 5.x] test: fix reply.mediaTyp
chore(sponsor): add testmu ai by @Eomm in https://github.com/fastify/fastify/pull/6922 docs: add per-route logging for Google Cloud Functions by @slegarraga in https://github.com/fastify/fastify/pull/6907 test: remove @sinonjs/fake-timers b
fix: clear trailer state when removing all trailers by @Ram-blip in https://github.com/fastify/fastify/pull/6845 docs: document percent-decoded route params as untrusted input by @mcollina in https://github.com/fastify/fastify/pull/6903 doc
fix fastify version in fastify.js
fix: add http method override warning by @jean-michelet in https://github.com/fastify/fastify/pull/6879 fix(types): allow explicit http2: false in server options by @Tony133 in https://github.com/fastify/fastify/pull/6888 docs: clarify what
chore: Bump markdownlint-cli2 from 0.22.1 to 0.23.0 by @dependabot[bot] in https://github.com/fastify/fastify/pull/6839 fix: normalize method in findRoute by @Ram-blip in https://github.com/fastify/fastify/pull/6838 docs: fix incorrect desc
docs(type-providers): clarify as const usage by @smith558 in https://github.com/fastify/fastify/pull/6772 docs: fix broken and redirected links by @Eomm in https://github.com/fastify/fastify/pull/6817 docs: remove marko from @fastify/view e
feat: add request.mediaType by @climba03003 in https://github.com/fastify/fastify/pull/6653 docs: remove deprecated leveldb plugin and update ecosystem by @Tony133 in https://github.com/fastify/fastify/pull/6661 chore(sponsor): add bestfora
⚠️ Security Release This fixes CVE CVE-2026-33806 https://github.com/fastify/fastify/security/advisories/GHSA-247c-9743-5963. What's Changed chore: Fix port parsing by @jsumners in https://github.com/fastify/fastify/pull/6603 chore: upgrade
⚠️ Security Release This fixes CVE CVE-2026-3635 https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf. What's Changed docs(readme): add @Tony133 to plugin team by @Tony133 in https://github.com/fastify/fastify/pull/656
docs(ecosystem): add @yeliex/fastify-problem-details by @yeliex in https://github.com/fastify/fastify/pull/6546 Revert "chore: upgrade borp to v1.0.0" by @climba03003 in https://github.com/fastify/fastify/pull/6564 docs: document body valid
⚠️ Security Release Fixes "Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation": https://github.com/fastify/fastify/security/advisories/GHSA-573f-x89g-hqp9. CVE-2026-3419
docs(request): add host security warning references by @mcollina in https://github.com/fastify/fastify/pull/6476 docs: fix note style by @Fdawgs in https://github.com/fastify/fastify/pull/6487 chore: rename deploy website ci by @Eomm in htt
⚠️ Security Release Fix https://github.com/fastify/fastify/security/advisories/GHSA-mrq3-vjjr-p77c CVE-2026-25224. What's Changed docs: update Reply.send() documentation for string serialization by @mcollina in https://github.com/fastify/fa
⚠️ Notice ⚠️ Parsing of the content-type header has been improved to a strict parser in PR #6414. This means only header values in the form described in RFC 9110 are accepted. What's Changed chore: npm ignore AI related files by @climba0300
chore: Bump actions/checkout from 5 to 6 by @dependabot[bot] in https://github.com/fastify/fastify/pull/6434 chore: updated version in the fastify.js by @Tony133 in https://github.com/fastify/fastify/pull/6446
docs: Improved firebase serverless guide about process remaining stuck by @alexandercerutti in https://github.com/fastify/fastify/pull/6380 docs: update migration guide with date-time breaking change by @craftsman01 in https://github.com/fa
refactor: rename source file names with kebab-case by @jean-michelet in https://github.com/fastify/fastify/pull/6331 ci(ci): check dependabot prs originate from repo by @Fdawgs in https://github.com/fastify/fastify/pull/6330 fix: accept hta
fix: fix typo of deprecation warning FSTDEP022 by @Uzlopak in https://github.com/fastify/fastify/pull/6313 docs(decorators): fix TypeScript inconsistency by @emicovi in https://github.com/fastify/fastify/pull/6224 chore: fix typos by @deini
fix: update typescript pino type to pick by @dancastillo in https://github.com/fastify/fastify/pull/6287 feat(types): router option types by @dancastillo in https://github.com/fastify/fastify/pull/6282 fix(types): Fix use of "esModuleIntero
docs: fix markdown linting issue by @Uzlopak in https://github.com/fastify/fastify/pull/6175 chore: removed simple-get from mkcalendar tests by @ilteoood in https://github.com/fastify/fastify/pull/6199 chore: removed simple-get from version
test: mv routes-* from tap by @jean-michelet in https://github.com/fastify/fastify/pull/6092 test: mv skip-reply-send from tap by @jean-michelet in https://github.com/fastify/fastify/pull/6094 test: mv plugins from tap by @jean-michelet in
docs: update Vercel section by @leerob in https://github.com/fastify/fastify/pull/6046 docs(ecosystem): add fastify-papr plugin by @inaiat in https://github.com/fastify/fastify/pull/6051 test: migrated helper and input validation to node te
⚠️ Security Release ⚠️ Unfortunately, v5.3.1 did not include a complete fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442. This is a follow-up patch to cover an edge case. What's Changed docs: fix arc
⚠️ Security Release ⚠️ Fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442 What's Changed test: migrate logger options to node test runner by @ilteoood in https://github.com/fastify/fastify/pull/6059 te
fix: wrong reply return type by @dangkyokhoang in https://github.com/fastify/fastify/pull/6026 feat: allow to access decorators by @jean-michelet in https://github.com/fastify/fastify/pull/5768 ci: continue-on-error on alternative runtime b
build: use static path instead of __filename by @climba03003 in https://github.com/fastify/fastify/pull/5922 fix(linting): fix linting error in error-handler.js by @Uzlopak in https://github.com/fastify/fastify/pull/5926 chore: Bump the dev
chore: org members reorder by @Eomm in https://github.com/fastify/fastify/pull/5898 docs(request): clarify request host functionality by @Fdawgs in https://github.com/fastify/fastify/pull/5904 chore(package): add fdawgs to contributors arra
docs: add HeroDevs mentions to README and LTS docs by @AndreAngelantoni in https://github.com/fastify/fastify/pull/5730 test: migrated reply-early-hints.test.js from tap to node:test by @Tony133 in https://github.com/fastify/fastify/pull/58
chore: Update Migration-Guide-V5.md by @jsumners in https://github.com/fastify/fastify/pull/5688 fix(guide-v5): wrong link for diagnostics channel by @corradopetrelli in https://github.com/fastify/fastify/pull/5693 chore: fix typo in reply-
add missing route shorthands by @Uzlopak in https://github.com/fastify/fastify/pull/4409 lib: drop setDefaultRoute and getDefaultRoute methods by @RafaelGSS in https://github.com/fastify/fastify/pull/4485 Sync next-branch by @github-actions
4.x25 releases
⚠️ Security Release ⚠️ Fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442.
fix(backport v4.x): config type in RouteShorthandOptions by @bastienmenis in https://github.com/fastify/fastify/pull/5527 feat(backport 4.x): add body parsing on copy move mkcol methods by @johaven in https://github.com/fastify/fastify/pull
[Backport 4.x] fix: server.listen listener is not cleanup properly by @github-actions in https://github.com/fastify/fastify/pull/5523 [Backport 4.x] test: fix test finished earlier than expected by @github-actions in https://github.com/fast
test: fix closing - pipelining by @climba03003 in https://github.com/fastify/fastify/pull/5486 refactor(backport v4.x): change reply.redirect() signature (#5483) by @gurgunday in https://github.com/fastify/fastify/pull/5484 refactor(backpor
docs(request): update request page by @Tony133 in https://github.com/fastify/fastify/pull/5343 ci: Add Nsolid runtime to CI and Integration tests by @riosje in https://github.com/fastify/fastify/pull/5332 docs(Ecosystem): add fastify-i18n,
fix: typo in module exports by @lirantal in https://github.com/fastify/fastify/pull/5316 docs(ts): Fix links by @rozzilla in https://github.com/fastify/fastify/pull/5308 fix: cb is not a function at fallbackErrorHandler by @Uzlopak in https
docs(ecosystem): adds fastify-hana to the community plugins list by @yoav0gal in https://github.com/fastify/fastify/pull/5289 docs: fix misattributed property parent in deprecation warning: request.elapsedTime by @mscottnelson in https://gi
docs(ecosystem): add missing plugins to core list by @Fdawgs in https://github.com/fastify/fastify/pull/5234 ci: CITGM github workflow by @Uzlopak in https://github.com/fastify/fastify/pull/5233 chore: bump find-may-way to v8.0.0 by @mcolli
fix: npm run test:watch by @domdomegg in https://github.com/fastify/fastify/pull/5221 fix: always consume stream payloads when responding to 204 with no body by @mcollina in https://github.com/fastify/fastify/pull/5231 docs: update setError
fix: route constraints by @climba03003 in https://github.com/fastify/fastify/pull/5207 fix: Better plugin name detection for FSTWRN002 by @mcollina in https://github.com/fastify/fastify/pull/5209 chore: at-large project by @Eomm in https://
feat: Improve RouteShorthandOptions['constraints'] type by @Fcmam5 in https://github.com/fastify/fastify/pull/5097 fix: add @eomm and @jsumners as lead maintainers by @mcollina in https://github.com/fastify/fastify/pull/5115 fix: reply.send
fix: timeout on citgm tests by @simone-sanfratello in https://github.com/fastify/fastify/pull/5101 chore: add missing use strict directives by @Fdawgs in https://github.com/fastify/fastify/pull/5106
fix: build problems when Symbol.asyncDispose type is not available. by @arthurfiorette in https://github.com/fastify/fastify/pull/5096
fix: citgm by @simone-sanfratello in https://github.com/fastify/fastify/pull/5075 fix: HEAD route reseting by @ivan-tymoshenko in https://github.com/fastify/fastify/pull/5090
docs: Add blank line before onclose hook heading by @kadoshita in https://github.com/fastify/fastify/pull/5042 build(dependabot): ignore tap major updates by @Fdawgs in https://github.com/fastify/fastify/pull/5047 chore: Bump actions/checko
fix: add routeOptions.schema to types by @Uzlopak in https://github.com/fastify/fastify/pull/5035
fix: correct warnings for request.routerPath and request.routerMethod by @Uzlopak in https://github.com/fastify/fastify/pull/5032 fix: add routeOptions.config to types by @mcollina in https://github.com/fastify/fastify/pull/5034
test: reduce output of reqIdGenFactory.test.js by @Uzlopak in https://github.com/fastify/fastify/pull/5012 feat: Add onListen Hook by @BrendenInhelder in https://github.com/fastify/fastify/pull/4899 docs(readme): avoid line breaks in docume
A spurious file (a test run result) was added to the package, which was now removed.
chore: Bump the dev-dependencies group with 1 update by @dependabot in https://github.com/fastify/fastify/pull/5002 docs(ecosystem): add fastify-rabbitmq to ecosystem.md by @Bugs5382 in https://github.com/fastify/fastify/pull/5000 docs(ecos
make FastifySchemaValidationError.params wider by @cm-ayf in https://github.com/fastify/fastify/pull/4476 docs(ecosystem): add fastify-hashids by @andersonjoseph in https://github.com/fastify/fastify/pull/4934 fix: hasPlugin does not track
chore: remove license-checker package by @Uzlopak in https://github.com/fastify/fastify/pull/4914 chore: remove pump devDependency by @Uzlopak in https://github.com/fastify/fastify/pull/4913 ci: create artifacts in coverage workflows by @Uz
build(deps-dev): Bump @sinclair/typebox from 0.28.20 to 0.29.1 by @dependabot in https://github.com/fastify/fastify/pull/4877 Update Prototype-Poisoning.md by @ed-henrique in https://github.com/fastify/fastify/pull/4879 docs: adjust line fo
fix(typescript): route config should not pass url and method by @climba03003 in https://github.com/fastify/fastify/pull/4872 Overload DecorationMethod to fix #4870 by @voxpelli in https://github.com/fastify/fastify/pull/4874 fix: Type infer
docs(typescript): fix typo by @jon-codes in https://github.com/fastify/fastify/pull/4861 docs(testing): add plugin testing guide by @Ekott2006 in https://github.com/fastify/fastify/pull/4849 docs: fix platformatic-cloud anchor id by @sher i