Fastify

6 posts tagged with “Fastify”

BREAKING: CVE-2026-76169 lets malformed URLs skip Fastify not-found auth
cvefastifyauth-bypass

BREAKING: CVE-2026-76169 lets malformed URLs skip Fastify not-found auth

How to fix CVE-2026-76169: upgrade fastify to 5.12.2

Sep 4, 2026
Read
BREAKING: CVE-2026-85184 lets absolute-form requests skip Fastify middie auth
cvefastifymiddie

BREAKING: CVE-2026-85184 lets absolute-form requests skip Fastify middie auth

How to fix CVE-2026-85184: upgrade @fastify/middie to 9.3.4

Sep 4, 2026
Read
CVE-2026-75899: fast-uri SSRF via Repeated Hostname Decoding
cvefast-urissrf

CVE-2026-75899: fast-uri SSRF via Repeated Hostname Decoding

How to fix CVE-2026-75899: upgrade fast-uri to 2.4.5, 3.1.6, or 4.1.3. Nested percent-encoding in a hostname becomes localhost after normalize() or resolve(). Not RCE. Same patch train as three sibling High SSRF and host-confusion GHSAs.

Aug 24, 2026
Read
BREAKING: CVE-2026-18549 - @fastify/multipart Aborted Upload DoS
cvesecurityvulnerability

BREAKING: CVE-2026-18549 - @fastify/multipart Aborted Upload DoS

CVE-2026-18549 lets unauthenticated clients leak temp files and hang request handlers in @fastify/multipart <10.1.1, causing disk and event-loop exhaustion. Upgrade to 10.1.1.

Aug 16, 2026
Read
BREAKING: CVE-2026-18165 - @fastify/oauth2 Login CSRF via Plantable State Cookies
cvesecurityvulnerability

BREAKING: CVE-2026-18165 - @fastify/oauth2 Login CSRF via Plantable State Cookies

@fastify/oauth2 7.2.0 through 8.2.0 accepts plantable OAuth state cookies from related hosts, enabling login CSRF. Upgrade to 8.3.0 and enable hostPrefixedCookies.

Aug 15, 2026
Read
BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass
cvesecurityvulnerability

BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass

CVE-2026-18500 lets @fastify/jwt before 10.2.2 override a route-specific verification key with the global secret, breaking JWT authorization-domain separation. NVD scores it 8.1 HIGH.

Aug 15, 2026
Read