Skip to content
Noroxi

fastify records

64 published records for vendor fastify.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
98.4%
Median publish → KEV
No record has entered KEV

All records

64 records
  • Denial of service in Fastify via Content-Type header

    HighCVSS 7.5No exploitEPSS 59%

    fastify · fastifyOct 10, 2022

  • @fastify/http-proxy vulnerable to prefix escape via WebSocket path traversal

    CriticalCVSS 10.0No exploitEPSS 1%

    fastify · fastify\/http-proxyJul 18, 2026

  • @fastify/http-proxy vulnerable to prefix escape via URL-encoded characters

    CriticalCVSS 10.0No exploitEPSS 0%

    fastify · fastify\/http-proxyJul 18, 2026

  • @fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision

    CriticalCVSS 10.0No exploitEPSS 0%

    fastify · fastify\/reply-fromJul 18, 2026

  • CVE-2026-6270
    36Monitor

    @fastify/middie vulnerable to middleware authentication bypass in child plugin scopes

    CriticalCVSS 9.1No exploitEPSS 1%

    fastify · fastify\/middieApr 16, 2026

  • @fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers

    CriticalCVSS 9.0No exploitEPSS 1%

    fastify · fastify\/http-proxyApr 15, 2026

  • @fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)

    CriticalCVSS 9.1No exploitEPSS 1%

    fastify · fastify\/expressApr 15, 2026

  • @fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes

    CriticalCVSS 9.1No exploitEPSS 1%

    fastify · fastify\/expressApr 15, 2026

  • @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target

    CriticalCVSS 9.1No exploitEPSS 1%

    fastify · fastify\/middieSep 4, 2026

  • CVE-2026-6556
    36Monitor

    @fastify/express vulnerable to middleware bypass via non-string mount paths in prefixed plugins

    CriticalCVSS 9.1No exploitEPSS 1%

    fastify · fastify\/expressJun 30, 2026

  • @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values

    CriticalCVSS 9.1No exploitEPSS 1%

    fastify · fastify\/middieJul 1, 2026

  • @fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option

    CriticalCVSS 9.1No exploitEPSS 0%

    fastify · fastify\/middieApr 16, 2026

  • @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header

    CriticalCVSS 9.1No exploitEPSS 0%

    fastify · fastify\/aws-lambdaAug 3, 2026

  • A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox use

    HighCVSS 8.8No exploitEPSS 1%

    fastify · fastify-staticOct 14, 2021

  • Cross-site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 1%

    fastify · fastify-csrfJan 19, 2021

  • All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users.

    HighCVSS 8.8No exploitEPSS 1%

    fastify · oauth2Jul 4, 2023

  • Fastify Middie Middleware Path Bypass

    HighCVSS 8.8No exploitEPSS 1%

    fastify · fastify\/middieJan 19, 2026

  • Fastify vulnerable to Cross-Site Request Forgery (CSRF) attack via incorrect content type

    HighCVSS 8.8No exploitEPSS 0%

    fastify · fastifyNov 22, 2022

  • Session fixation in fastify-passport

    HighCVSS 8.1No exploitEPSS 1%

    fastify · passportApr 21, 2023

  • CVE-2026-2880
    32Monitor

    @fastify/middie has an improper path normalization vulnerability

    HighCVSS 8.2No exploitEPSS 1%

    fastify · fastify\/middieFeb 27, 2026

  • fastify vulnerable to request body replacement via an async validation result collision

    HighCVSS 8.1No exploitEPSS 0%

    fastify · fastifySep 4, 2026

  • @fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key

    HighCVSS 8.1No exploitEPSS 0%

    fastify · fastify\/jwtAug 15, 2026

  • Denial of Service (DoS)

    HighCVSS 7.5No exploitEPSS 2%

    fastify · fastify-multipartFeb 11, 2022

  • CVE-2018-3711
    31Monitor

    Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and

    HighCVSS 7.5No exploitEPSS 2%

    fastify · fastifyJun 6, 2018

  • CVE-2020-8136
    30Monitor

    Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests b

    HighCVSS 7.5No exploitEPSS 1%

    fastify · fastify-multipartMar 20, 2020