fastify Latest Vulnerabilities
Latest vulnerabilities published by fastify
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
Vulnerability in Fastify Applications Affecting Content-Type Validation
CVE-2026-33806FastifyFastify7.5HIGHSpoofing Vulnerability in Fastify Framework by Fastify Team
CVE-2026-3635FastifyFastify6.1MEDIUMFastify Malformed Content-Type Header Vulnerability - Fastify
CVE-2026-3419FastifyFastify5.3MEDIUMValidation Bypass Vulnerability in Fastify Web Framework for Node.js
CVE-2026-25223FastifyFastify7.5HIGHDenial-of-Service Vulnerability in Fastify Web Framework for Node.js
CVE-2026-25224FastifyFastify3.7LOWMiddleware Bypass in Fastify Plugin by Fastify
CVE-2026-22037FastifyFastify-express8.4HIGHMiddleware Bypass Vulnerability in @fastify/middie Plugin
CVE-2026-22031FastifyMiddie8.4HIGHUnauthenticated Route Access in Fastify Reply From Plugin
CVE-2025-66415FastifyFastify-reply-from6.9MEDIUMValidation Bypass in Fastify Web Framework Affecting Node.js Applications
CVE-2025-32442FastifyFastify7.5HIGHImproper Temporary File Management in Fastify Multipart Plugin
CVE-2025-24033FastifyFastify-multipart7.5HIGHSession Cookie Hijacking Vulnerability in Fastify Session Plugin by Fastify
CVE-2024-35220Fastify@fastify/sessionFestify Secure Session Plugin Patches Issue Allowing Unlimited Session Renewal
CVE-2024-31999FastifyFastify-secure-session7.4HIGHDefault swagger-ui configuration exposes all files in the module
CVE-2024-22207FastifyFastify-swagger-uiEPSS 14%5.3MEDIUMSecurity Bypass in Fastify Plugin for HTTP Request Forwarding from Fastify
CVE-2023-51701FastifyFastify-reply-from5.3MEDIUMSession fixation in fastify-passport
CVE-2023-29019FastifyFastify-passport8.1HIGHCross site request forgery token fixation in fastify-passport
CVE-2023-29020FastifyFastify-passport6.5MEDIUMBypass of CSRF protection in the presence of predictable userInfo in @fastify/csrf-protection
CVE-2023-27495FastifyCsrf-protection5.3MEDIUM@fastify/multipart vulnerable to DoS due to unlimited number of parts
CVE-2023-25576FastifyFastify-multipart7.5HIGHFastify vulnerable to Cross-Site Request Forgery (CSRF) attack via incorrect content type
CVE-2022-41919FastifyFastify4.2MEDIUMfastify-websocket vulnerable to uncaught exception via crash on malformed packet
CVE-2022-39386FastifyFastify-websocket7.5HIGHDenial of service in Fastify via Content-Type header
CVE-2022-39288FastifyFastify7.5HIGHPotential Timing Attack Vector in @fastify/bearer-auth
CVE-2022-31142FastifyFastify-bearer-auth7.5HIGHNo verification of commits origin in github-action-merge-dependabot
CVE-2022-29220FastifyGithub-action-merge-de...6.5MEDIUMDenial of Service (DoS)
CVE-2021-23597FastifyFastify-multipart7.5HIGHRedirect Vulnerability in Fastify-Static Module by Fastify
CVE-2021-22963FastifyHttps://github.com/fas...6.1MEDIUM