fastify
40 known vulnerabilities · 0 critical · 8 high
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
Denial of Service vulnerability with large JSON payloads in fastify
Fastify: Incorrect Content-Type parsing can lead to CSRF attack
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header
fastify vulnerable to denial of service via malicious Content-Type
Fastify's Content-Type header tab character allows body validation bypass
Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
@fastify/oauth2 vulnerable to Cross Site Request Forgery due to reused Oauth2 state
Fastify's connection header abuse enables stripping of proxy-added headers
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
@fastify/static vulnerable to route guard bypass via encoded path separators
fastify/websocket vulnerable to uncaught exception via crash on malformed packet
Duplicate Advisory: Nest has a Fastify URL Encoding Middleware Bypass
@fastify/express's middleware path doubling causes authentication bypass in child plugin scopes
@fastify/accepts-serializer Vulnerable to Denial of Service via Unbounded Accept Header Cache Growth
@fastify/static vulnerable to path traversal in directory listing
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
@fastify/middie has Improper Path Normalization when Using Path-Scoped Middleware
Lack of protection against cookie tossing attacks in fastify-csrf
@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)
URL Redirection to Untrusted Site ('Open Redirect') in fastify-static
Malicious code in fastify-tfb (npm)
Nest: Middleware Bypass on Fastify via Trailing Slash
Malicious code in plugin-fastify (npm)
Malicious code in fastify-addon (npm)
Malicious code in @mastra/fastify (npm)
@fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)