Catalog / Fastify

Fastify security advisories

All 14 advisories Fastify has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
1414 carry a CVE
high
8
medium
5
low
1
Fix in the archive
12of 14 matched to a release
Oldest
10 Oct 20223.9 years ago

2 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-84504high

fastify vulnerable to request body replacement via an async validation result collision

GHSA-667r-xxjv-c9mmFixed in 5.12.2
CVE-2026-76169high

fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers

GHSA-p68q-wchp-6fh7Fixed in 5.12.2
CVE-2026-84428high

fastify vulnerable to header validation bypass via incomplete schema case normalization

GHSA-9q9j-q6p8-xq58Fixed in 5.12.2
CVE-2026-18504medium

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

GHSA-w2qp-rph6-63g4Fixed in 5.12.1
CVE-2026-3635medium

request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function

GHSA-444r-cwp2-x5xfFixed in 5.8.3
CVE-2026-3419medium

Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation

GHSA-573f-x89g-hqp9Fixed in 5.8.1
CVE-2022-41919medium

Incorrect Content-Type parsing can lead to CSRF attack

GHSA-3fjj-p79j-c9hhFixed in 4.10.2, not held here
CVE-2022-39288high

Deny of service via malicious Content-Type

GHSA-455w-c45v-86rgFixed in 4.8.1, not held here