CVE Tools

Fastify

27 CVEs tracked since 2021. Since Oct 2021, none of them reached CISA KEV.

Fastify CVEs per month

Oct 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Fastify CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-1020
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-0480
2026-05null or fewer
2026-06null or fewer
2026-07null or fewer
2026-08100
2026-0970

Products

The products that kept showing up in Fastify's monthly top three, with their CVEs summed over those months.

  1. Fastify72 months
  2. Fastify\/middie32 months
  3. @fastify/express21 month
  4. Fastify-multipart21 month
  5. Fastify-static21 month
  6. Fastify\/busyboy21 month
  7. Fastify\/express21 month
  8. Fastify\/http-proxy11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Fastify.

  1. CVE-2026-92081fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses5.9
  2. CVE-2026-84428fastify vulnerable to header validation bypass via incomplete schema case normalization7.5
  3. CVE-2026-84469fastify vulnerable to request validation bypass via skipped boolean false schemas7.5
  4. CVE-2026-76169fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers7.5
  5. CVE-2026-84504fastify vulnerable to request body replacement via an async validation result collision8.1
  6. CVE-2026-85184@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target9.1
  7. CVE-2026-85124@fastify/http-proxy vulnerable to prefix escape via backslash dot-segments7.5
  8. CVE-2026-74866@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and name5.8
  9. CVE-2026-16732fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count6.1
  10. CVE-2026-18504fastify vulnerable to schema validation bypass via root primitive coercion mismatch5.4
  11. CVE-2026-18165@fastify/oauth2 vulnerable to Login CSRF via plantable OAuth state cookies4.2
  12. CVE-2026-19474@fastify/multipart vulnerable to Denial of Service via temporary file leak on aborted upload7.5
  13. CVE-2026-18549@fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit7.5
  14. CVE-2026-18500@fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key8.1
  15. CVE-2026-19484@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary7.5

The record

Peak rank
#139 in Apr 2026
Busiest month shown
Aug 2026, 10 CVEs
Months with a KEV entry
0 since Oct 2021
Monthly snapshots
4 since 2021
Fastify's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store