fastify vulnerable to request body replacement via an async validation result collision
Fastify security advisories
All 14 advisories Fastify has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 1414 carry a CVE
- high
- 8
- medium
- 5
- low
- 1
- Fix in the archive
- 12of 14 matched to a release
- Oldest
- 10 Oct 20223.9 years ago
2 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productfastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
fastify vulnerable to request validation bypass via skipped boolean false schemas
fastify vulnerable to header validation bypass via incomplete schema case normalization
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
Body Schema Validation Bypass via Leading Space in Content-Type Header
request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function
Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
DoS via Unbounded Memory Allocation in sendWebStream
Content-Type header tab character allows body validation bypass
Invalid content-type parsing could lead to validation bypass
Incorrect Content-Type parsing can lead to CSRF attack
Deny of service via malicious Content-Type