Back

MEDIUM

fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses

Published Sep 16, 2026

Description

fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fastify unconditionally sets the Transfer-Encoding: chunked header, which is forbidden on HTTP/2, so Node.js throws while serializing the response headers. The exception is not caught and becomes an uncaughtException, so a single unauthenticated HTTP/2 request to any route that uses trailers crashes the server process and drops all in-flight requests, and it can be repeated on every restart. The issue is fixed in fastify 5.12.5, and users should upgrade to 5.12.5 or later. As a workaround, avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until upgrading.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner openjs
Published Sep 16, 2026
Updated Sep 16, 2026
Reserved Sep 15, 2026
CISA Vulnrichment
Updated Sep 16, 2026
NVD
Status Awaiting Analysis
Modified Sep 16, 2026
Red Hat
Severity Moderate
Public date Sep 16, 2026
GHSA-4MH8-R7RC-XPVC