Vulnerabilidades em fastify
35 resultadosAnálise Vexday
Fastify apresenta 28 vulnerabilidades registradas, das quais 4 são críticas, sem episódios de exploração ativa documentada. A fraqueza dominante é ausência de proteção CSRF (CWE-352), indicando risco principalmente em contextos de requisições não autenticadas; a ausência de publicações recentes sugere que o risco está estabilizado, não emergente.
CVE-2024-35220HIGH@fastify/session reuses destroyed session cookieEPSS 0.4%CVE-2026-33807CRITICAL@fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopesEPSS 0.4%CVE-2022-41919MEDIUMFastify vulnerable to Cross-Site Request Forgery (CSRF) attack via incorrect content typeEPSS 0.4%CVE-2026-84504HIGHfastify vulnerable to request body replacement via an async validation result collisionEPSS 0.4%CVE-2026-92081MEDIUMfastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responsesEPSS 0.4%CVE-2023-29020MEDIUMCross site request forgery token fixation in fastify-passportEPSS 0.4%CVE-2026-22037HIGH@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)EPSS 0.4%CVE-2026-3419MEDIUMFastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass ValidationEPSS 0.4%CVE-2023-27495MEDIUMBypass of CSRF protection in the presence of predictable userInfo in @fastify/csrf-protectionEPSS 0.3%CVE-2026-18504MEDIUMfastify vulnerable to schema validation bypass via root primitive coercion mismatchEPSS 0.3%CVE-2026-84428HIGHfastify vulnerable to header validation bypass via incomplete schema case normalizationEPSS 0.3%CVE-2026-84469HIGHfastify vulnerable to request validation bypass via skipped boolean false schemasEPSS 0.3%CVE-2025-66415MEDIUMfastify-reply-from bypass of reply forwardingEPSS 0.2%CVE-2026-16732MEDIUMfastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-countEPSS 0.1%CVE-2026-3635MEDIUMFastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust functionEPSS 0.1%