Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/fastify — 10 CVEs · VulnScope
pkg:npm/
fastify
10 total CVEs
HIGH
5
MEDIUM
3
LOW
1
✅ Check your installed version
Check
All known vulnerabilities
HIGH
7.5
CVE-2026-33806
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header
>= 5.3.2, < 5.8.5
HIGH
7.5
CVE-2026-25223
Fastify's Content-Type header tab character allows body validation bypass
from 0, < 5.7.2
HIGH
7.5
CVE-2025-32442
Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass
>= 5.0.0, < 5.3.2
HIGH
7.5
fastify vulnerable to denial of service via malicious Content-Type
>= 4.0.0, < 4.8.1
HIGH
7.5
Denial of Service vulnerability with large JSON payloads in fastify
from 0, < 0.38.0
MEDIUM
6.1
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
from 0, < 5.8.3
MEDIUM
5.3
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
>= 5.7.2, < 5.8.1
MEDIUM
4.2
Fastify: Incorrect Content-Type parsing can lead to CSRF attack
>= 4.0.0, < 4.10.2
LOW
3.7
Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
from 0, < 5.7.3
—
Denial of service in fastify
from 0, < 2.15.1
CVE-2022-39288
CVE-2018-3711
CVE-2026-3635
CVE-2026-3419
CVE-2022-41919
CVE-2026-25224
CVE-2020-8192