Fastify
21 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Fastify, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Fastify CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 2 |
| 2026-03 | 2 |
| 2026-04 | 3 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 2 |
| 2026-09 | 5 |
Severity
How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High11
- Medium7
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Fastify.
- CVE-2026-92081fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses5.9
- CVE-2026-84428fastify vulnerable to header validation bypass via incomplete schema case normalization7.5
- CVE-2026-84469fastify vulnerable to request validation bypass via skipped boolean false schemas7.5
- CVE-2026-76169fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers7.5
- CVE-2026-84504fastify vulnerable to request body replacement via an async validation result collision8.1
- CVE-2026-16732fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count6.1
- CVE-2026-18504fastify vulnerable to schema validation bypass via root primitive coercion mismatch5.4
- CVE-2026-42349Clerk: Authorization bypass when combining organization, billing, or reverification checks8.1
- CVE-2026-33807@fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes9.1
- CVE-2026-33808@fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)9.1
- CVE-2026-33806fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header7.5
- CVE-2026-3635Fastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function6.1
- CVE-2026-3419Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation5.3
- CVE-2026-25223Fastify's Content-Type header tab character allows body validation bypass7.5
- CVE-2026-25224Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream3.7
Product grouping is registry-driven, with AI assist and human review. How it works