fastify records
64 published records for vendor fastify.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 98.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-436 Interpretation Conflict7
- CWE-20 Improper Input Validation6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-400 Uncontrolled Resource Consumption4
- CWE-770 Allocation of Resources Without Limits or Throttling4
The weakness classes this vendor ships most often: where to look.
CWEAll records
64 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
48Plan | CVE-2022-39288No exploit | Denial of service in Fastify via Content-Type headerfastify · fastify · CWE-754 | High7.5 | — | 59.2% | Oct 10, 2022 |
40Plan | CVE-2026-15631No exploit | @fastify/http-proxy vulnerable to prefix escape via WebSocket path traversalfastify · fastify\/http-proxy · CWE-22 | Critical10.0 | — | 0.5% | Jul 18, 2026 |
40Plan | CVE-2026-16117No exploit | @fastify/http-proxy vulnerable to prefix escape via URL-encoded charactersfastify · fastify\/http-proxy · CWE-20 | Critical10.0 | — | 0.4% | Jul 18, 2026 |
40Plan | CVE-2026-16158No exploit | @fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collisionfastify · fastify\/reply-from · CWE-441 | Critical10.0 | — | 0.4% | Jul 18, 2026 |
36Monitor | CVE-2026-6270No exploit | @fastify/middie vulnerable to middleware authentication bypass in child plugin scopesfastify · fastify\/middie · CWE-436 | Critical9.1 | — | 0.6% | Apr 16, 2026 |
36Monitor | CVE-2026-33805No exploit | @fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headersfastify · fastify\/http-proxy · CWE-644 | Critical9.0 | — | 0.6% | Apr 15, 2026 |
36Monitor | CVE-2026-33808No exploit | @fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)fastify · fastify\/express · CWE-436 | Critical9.1 | — | 0.6% | Apr 15, 2026 |
36Monitor | CVE-2026-33807No exploit | @fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopesfastify · fastify\/express · CWE-436 | Critical9.1 | — | 0.5% | Apr 15, 2026 |
36Monitor | CVE-2026-85184No exploit | @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request targetfastify · fastify\/middie · CWE-436 | Critical9.1 | — | 0.5% | Sep 4, 2026 |
36Monitor | CVE-2026-6556No exploit | @fastify/express vulnerable to middleware bypass via non-string mount paths in prefixed pluginsfastify · fastify\/express · CWE-285 | Critical9.1 | — | 0.5% | Jun 30, 2026 |
36Monitor | CVE-2026-14198No exploit | @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter valuesfastify · fastify\/middie · CWE-436 | Critical9.1 | — | 0.5% | Jul 1, 2026 |
36Monitor | CVE-2026-33804No exploit | @fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes optionfastify · fastify\/middie · CWE-436 | Critical9.1 | — | 0.5% | Apr 16, 2026 |
36Monitor | CVE-2026-18248No exploit | @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event headerfastify · fastify\/aws-lambda · CWE-345 | Critical9.1 | — | 0.4% | Aug 3, 2026 |
35Monitor | CVE-2021-22964No exploit | A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox usefastify · fastify-static · CWE-400 | High8.8 | — | 1.0% | Oct 14, 2021 |
35Monitor | CVE-2020-28482No exploit | Cross-site Request Forgery (CSRF)fastify · fastify-csrf · CWE-200 | High8.8 | — | 1.0% | Jan 19, 2021 |
35Monitor | CVE-2023-31999No exploit | All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users.fastify · oauth2 · CWE-352 | High8.8 | — | 0.7% | Jul 4, 2023 |
35Monitor | CVE-2026-22031No exploit | Fastify Middie Middleware Path Bypassfastify · fastify\/middie · CWE-177 | High8.8 | — | 0.5% | Jan 19, 2026 |
35Monitor | CVE-2022-41919No exploit | Fastify vulnerable to Cross-Site Request Forgery (CSRF) attack via incorrect content typefastify · fastify · CWE-352 | High8.8 | — | 0.4% | Nov 22, 2022 |
32Monitor | CVE-2023-29019No exploit | Session fixation in fastify-passportfastify · passport · CWE-384 | High8.1 | — | 0.8% | Apr 21, 2023 |
32Monitor | CVE-2026-2880No exploit | @fastify/middie has an improper path normalization vulnerabilityfastify · fastify\/middie · CWE-20 | High8.2 | — | 0.5% | Feb 27, 2026 |
32Monitor | CVE-2026-84504No exploit | fastify vulnerable to request body replacement via an async validation result collisionfastify · fastify · CWE-20 | High8.1 | — | 0.4% | Sep 4, 2026 |
32Monitor | CVE-2026-18500No exploit | @fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request keyfastify · fastify\/jwt · CWE-347 | High8.1 | — | 0.3% | Aug 15, 2026 |
31Monitor | CVE-2021-23597No exploit | Denial of Service (DoS)fastify · fastify-multipart · CWE-1321 | High7.5 | — | 2.0% | Feb 11, 2022 |
31Monitor | CVE-2018-3711No exploit | Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" andfastify · fastify · CWE-770 | High7.5 | — | 1.8% | Jun 6, 2018 |
30Monitor | CVE-2020-8136No exploit | Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests bfastify · fastify-multipart · CWE-400 | High7.5 | — | 1.5% | Mar 20, 2020 |
- CVE-2022-3928848Plan
Denial of service in Fastify via Content-Type header
HighCVSS 7.5No exploitEPSS 59%fastify · fastifyOct 10, 2022
- CVE-2026-1563140Plan
@fastify/http-proxy vulnerable to prefix escape via WebSocket path traversal
CriticalCVSS 10.0No exploitEPSS 1%fastify · fastify\/http-proxyJul 18, 2026
- CVE-2026-1611740Plan
@fastify/http-proxy vulnerable to prefix escape via URL-encoded characters
CriticalCVSS 10.0No exploitEPSS 0%fastify · fastify\/http-proxyJul 18, 2026
- CVE-2026-1615840Plan
@fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision
CriticalCVSS 10.0No exploitEPSS 0%fastify · fastify\/reply-fromJul 18, 2026
- CVE-2026-627036Monitor
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
CriticalCVSS 9.1No exploitEPSS 1%fastify · fastify\/middieApr 16, 2026
- CVE-2026-3380536Monitor
@fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers
CriticalCVSS 9.0No exploitEPSS 1%fastify · fastify\/http-proxyApr 15, 2026
- CVE-2026-3380836Monitor
@fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)
CriticalCVSS 9.1No exploitEPSS 1%fastify · fastify\/expressApr 15, 2026
- CVE-2026-3380736Monitor
@fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes
CriticalCVSS 9.1No exploitEPSS 1%fastify · fastify\/expressApr 15, 2026
- CVE-2026-8518436Monitor
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
CriticalCVSS 9.1No exploitEPSS 1%fastify · fastify\/middieSep 4, 2026
- CVE-2026-655636Monitor
@fastify/express vulnerable to middleware bypass via non-string mount paths in prefixed plugins
CriticalCVSS 9.1No exploitEPSS 1%fastify · fastify\/expressJun 30, 2026
- CVE-2026-1419836Monitor
@fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values
CriticalCVSS 9.1No exploitEPSS 1%fastify · fastify\/middieJul 1, 2026
- CVE-2026-3380436Monitor
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
CriticalCVSS 9.1No exploitEPSS 0%fastify · fastify\/middieApr 16, 2026
- CVE-2026-1824836Monitor
@fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header
CriticalCVSS 9.1No exploitEPSS 0%fastify · fastify\/aws-lambdaAug 3, 2026
- CVE-2021-2296435Monitor
A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox use
HighCVSS 8.8No exploitEPSS 1%fastify · fastify-staticOct 14, 2021
- CVE-2020-2848235Monitor
Cross-site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 1%fastify · fastify-csrfJan 19, 2021
- CVE-2023-3199935Monitor
All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users.
HighCVSS 8.8No exploitEPSS 1%fastify · oauth2Jul 4, 2023
- CVE-2026-2203135Monitor
Fastify Middie Middleware Path Bypass
HighCVSS 8.8No exploitEPSS 1%fastify · fastify\/middieJan 19, 2026
- CVE-2022-4191935Monitor
Fastify vulnerable to Cross-Site Request Forgery (CSRF) attack via incorrect content type
HighCVSS 8.8No exploitEPSS 0%fastify · fastifyNov 22, 2022
- CVE-2023-2901932Monitor
Session fixation in fastify-passport
HighCVSS 8.1No exploitEPSS 1%fastify · passportApr 21, 2023
- CVE-2026-288032Monitor
@fastify/middie has an improper path normalization vulnerability
HighCVSS 8.2No exploitEPSS 1%fastify · fastify\/middieFeb 27, 2026
- CVE-2026-8450432Monitor
fastify vulnerable to request body replacement via an async validation result collision
HighCVSS 8.1No exploitEPSS 0%fastify · fastifySep 4, 2026
- CVE-2026-1850032Monitor
@fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key
HighCVSS 8.1No exploitEPSS 0%fastify · fastify\/jwtAug 15, 2026
- CVE-2021-2359731Monitor
Denial of Service (DoS)
HighCVSS 7.5No exploitEPSS 2%fastify · fastify-multipartFeb 11, 2022
- CVE-2018-371131Monitor
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and
HighCVSS 7.5No exploitEPSS 2%fastify · fastifyJun 6, 2018
- CVE-2020-813630Monitor
Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests b
HighCVSS 7.5No exploitEPSS 1%fastify · fastify-multipartMar 20, 2020