Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
Published Feb 3, 2026
3.7
LOWCVSS 3.1
EPSS 0.52%
Description
Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applications that return a ReadableStream (or Response with a Web Stream body) via reply.send() are impacted. A slow or non-reading client can trigger unbounded buffering when backpressure is ignored, leading to process crashes or severe degradation. This issue has been patched in version 5.7.3.
Affected products
-
- Version < 5.7.3StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-dashboard-rhel8
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-dashboard-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-gen-ai-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-model-registry-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/dashboard-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-dashboard-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-dashboard-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-gen-ai-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-model-registry-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/dashboard-rhel9 | Fix deferred | n/a |
fastify
npm
Introduced 0 Fixed 5.7.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | fastify | 0 | 5.7.3 |
Remediation
Red Hat statement
LOW. A denial-of-service flaw exists in Fastify's Web Streams response handling. This issue can lead to unbounded buffering and memory exhaustion when a remote client sends a slow or non-reading request to an application that uses `reply.send()` with a `ReadableStream` or `Response` with a Web Stream body. Red Hat products utilizing Fastify in this configuration are affected.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 4, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Feb–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.52% (0.00518) | 41.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.49% (0.00488) | 37.93th | v5 (v2026.06.15) |
| Feb 4, 2026 | 0.04% (0.00037) | 10.61th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2026-25224 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2436557 Issue Tracking
- https://github.com/advisories/GHSA-mrq3-vjjr-p77c Advisory
- https://github.com/fastify/fastify/commit/eb11156396f6a5fedaceed0140aed2b7f026be37 x_refsource_MISCPatch
- https://github.com/fastify/fastify/security/advisories/GHSA-mrq3-vjjr-p77c x_refsource_CONFIRMVendor Advisory
- https://hackerone.com/reports/3524779 x_refsource_MISCPermissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2026-25224
- https://www.cve.org/CVERecord?id=CVE-2026-25224
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-25224 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2436557 | Issue Tracking | |
| https://github.com/advisories/GHSA-mrq3-vjjr-p77c | Advisory | |
| https://github.com/fastify/fastify/commit/eb11156396f6a5fedaceed0140aed2b7f026be37 | x_refsource_MISCPatch | |
| https://github.com/fastify/fastify/security/advisories/GHSA-mrq3-vjjr-p77c | x_refsource_CONFIRMVendor Advisory | |
| https://hackerone.com/reports/3524779 | x_refsource_MISCPermissions Required | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-25224 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-25224 |
Change history (0)
No recorded changes yet.