fastify
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting fastify.
- CVE-2026-92081fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses5.9
- CVE-2026-84428fastify vulnerable to header validation bypass via incomplete schema case normalization7.5
- CVE-2026-84469fastify vulnerable to request validation bypass via skipped boolean false schemas7.5
- CVE-2026-76169fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers7.5
- CVE-2026-84504fastify vulnerable to request body replacement via an async validation result collision8.1
- CVE-2026-85184@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target9.1
- CVE-2026-85124@fastify/http-proxy vulnerable to prefix escape via backslash dot-segments7.5
- CVE-2026-74866@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and name5.8
- CVE-2026-16732fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count6.1
- CVE-2026-18504fastify vulnerable to schema validation bypass via root primitive coercion mismatch5.4
- CVE-2026-18165@fastify/oauth2 vulnerable to Login CSRF via plantable OAuth state cookies4.2
- CVE-2026-19474@fastify/multipart vulnerable to Denial of Service via temporary file leak on aborted upload7.5
- CVE-2026-18549@fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit7.5
- CVE-2026-18500@fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key8.1
- CVE-2026-19484@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary7.5