Fastify
This hub aggregates every CVE we track for Fastify, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
21
CVEs tracked
2
Critical
11
High
0
In CISA KEV
Severity distribution
HIGH11MEDIUM7CRITICAL2LOW1
Monthly trend
0
0
0
1
0
0
1
0
0
0
0
0
0
0
0
0
2
2
3
1
0
0
2
5
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Fastify.
- CVE-2026-92081fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses5.9
- CVE-2026-84428fastify vulnerable to header validation bypass via incomplete schema case normalization7.5
- CVE-2026-84469fastify vulnerable to request validation bypass via skipped boolean false schemas7.5
- CVE-2026-76169fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers7.5
- CVE-2026-84504fastify vulnerable to request body replacement via an async validation result collision8.1
- CVE-2026-16732fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count6.1
- CVE-2026-18504fastify vulnerable to schema validation bypass via root primitive coercion mismatch5.4
- CVE-2026-42349Clerk: Authorization bypass when combining organization, billing, or reverification checks8.1
- CVE-2026-33807@fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes9.1
- CVE-2026-33808@fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)9.1
- CVE-2026-33806fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header7.5
- CVE-2026-3635Fastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function6.1
- CVE-2026-3419Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation5.3
- CVE-2026-25223Fastify's Content-Type header tab character allows body validation bypass7.5
- CVE-2026-25224Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream3.7
Product normalization is registry-driven with AI assist and human review. How it works