fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
Published Sep 16, 2026
5.9
MEDIUMCVSS 3.1
EPSS 0.41%
Description
fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fastify unconditionally sets the Transfer-Encoding: chunked header, which is forbidden on HTTP/2, so Node.js throws while serializing the response headers. The exception is not caught and becomes an uncaughtException, so a single unauthenticated HTTP/2 request to any route that uses trailers crashes the server process and drops all in-flight requests, and it can be repeated on every restart. The issue is fixed in fastify 5.12.5, and users should upgrade to 5.12.5 or later. As a workaround, avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until upgrading.
Affected products
-
- Version 0StatusaffectedConstraints<5.12.5
- Version 5.12.5StatusunaffectedConstraints-
- Version
No data.
No data.
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-core-bff-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-dashboard-operator-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-dashboard-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-agent-ops-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-automl-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-autorag-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-eval-hub-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-gen-ai-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-maas-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-mlflow-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-model-registry-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/dashboard-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-core-bff-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-dashboard-operator-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-dashboard-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-agent-ops-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-automl-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-autorag-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-eval-hub-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-gen-ai-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-maas-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-mlflow-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-model-registry-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/dashboard-rhel9 | Fix deferred | n/a |
fastify
npm
Introduced 0 Fixed 5.12.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | fastify | 0 | 5.12.5 |
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-92081 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2535071 Issue Tracking
- https://cna.openjsf.org/security-advisories.html
- https://github.com/advisories/GHSA-4mh8-r7rc-xpvc Advisory
- https://github.com/fastify/fastify/commit/ad06a4c3fe8a944a904f38068249b18b8f552e90
- https://github.com/fastify/fastify/issues/6574
- https://github.com/fastify/fastify/releases/tag/v5.12.5
- https://github.com/fastify/fastify/security/advisories/GHSA-4mh8-r7rc-xpvc
- https://nvd.nist.gov/vuln/detail/CVE-2026-92081
- https://www.cve.org/CVERecord?id=CVE-2026-92081
Change history (0)
No recorded changes yet.