Vulnerabilidades en fastify

35 resultados
Análisis Vexday

Fastify apresenta 28 vulnerabilidades registradas, das quais 4 são críticas, sem episódios de exploração ativa documentada. A fraqueza dominante é ausência de proteção CSRF (CWE-352), indicando risco principalmente em contextos de requisições não autenticadas; a ausência de publicações recentes sugere que o risco está estabilizado, não emergente.

CVE-2026-33806HIGHfastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type HeaderEPSS 0.5%CVE-2022-29220MEDIUMNo verification of commits origin in github-action-merge-dependabotEPSS 0.5%CVE-2023-51701MEDIUM@fastify-reply-from JSON Content-Type parsing confusionEPSS 0.5%CVE-2026-3419MEDIUMFastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass ValidationEPSS 0.5%CVE-2024-35220HIGH@fastify/session reuses destroyed session cookieEPSS 0.4%CVE-2026-84504HIGHfastify vulnerable to request body replacement via an async validation result collisionEPSS 0.4%CVE-2026-92081MEDIUMfastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responsesEPSS 0.4%CVE-2022-41919MEDIUMFastify vulnerable to Cross-Site Request Forgery (CSRF) attack via incorrect content typeEPSS 0.4%CVE-2023-29020MEDIUMCross site request forgery token fixation in fastify-passportEPSS 0.4%CVE-2026-22037HIGH@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)EPSS 0.4%CVE-2023-27495MEDIUMBypass of CSRF protection in the presence of predictable userInfo in @fastify/csrf-protectionEPSS 0.3%CVE-2026-18504MEDIUMfastify vulnerable to schema validation bypass via root primitive coercion mismatchEPSS 0.3%CVE-2025-66415MEDIUMfastify-reply-from bypass of reply forwardingEPSS 0.2%CVE-2026-3635MEDIUMFastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust functionEPSS 0.2%CVE-2026-16732MEDIUMfastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-countEPSS 0.2%