fastify
OSS Librariesoss-project
Latest CVEs
The 15 most recently published vulnerabilities affecting fastify.
- CVE-2026-15144@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation7.3
- CVE-2026-18174@fastify/forwarded vulnerable to improper input validation via unstripped tab characters in X-Forwarded-For5.3
- CVE-2026-15074@fastify/static vulnerable to route guard bypass via path traversal7.5
- CVE-2026-7120@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths5.3
- CVE-2026-16117@fastify/http-proxy vulnerable to prefix escape via URL-encoded characters10.0
- CVE-2026-15631@fastify/http-proxy vulnerable to prefix escape via WebSocket path traversal8.7
- CVE-2026-16158@fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision8.7
- CVE-2026-14181@fastify/middie standalone engine vulnerable to Denial of Service via malformed percent-encoded paths7.5
- CVE-2026-14198@fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values9.1
- CVE-2026-6556@fastify/express vulnerable to middleware bypass via non-string mount paths in prefixed plugins9.1
- CVE-2026-7768@fastify/accepts-serializer vulnerable to Denial of Service via Unbounded Accept Header Cache Growth7.5
- CVE-2026-33804@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option7.4
- CVE-2026-6270@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes9.1
- CVE-2026-6410@fastify/static vulnerable to path traversal in directory listing5.3
- CVE-2026-6414@fastify/static vulnerable to route guard bypass via encoded path separators5.9