CVE Browser
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
fastify vulnerable to header validation bypass via incomplete schema case normalization
fastify vulnerable to request validation bypass via skipped boolean false schemas
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
fastify vulnerable to request body replacement via an async validation result collision
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
@fastify/http-proxy vulnerable to prefix escape via backslash dot-segments
@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and name
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
@fastify/oauth2 vulnerable to Login CSRF via plantable OAuth state cookies
@fastify/multipart vulnerable to Denial of Service via temporary file leak on aborted upload
@fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit
@fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
@fastify/static vulnerable to route guard bypass via non-canonical path segments
@fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header
@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation
@fastify/forwarded vulnerable to improper input validation via unstripped tab characters in X-Forwarded-For
@fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
@fastify/http-proxy vulnerable to prefix escape via URL-encoded characters
@fastify/http-proxy vulnerable to prefix escape via WebSocket path traversal
@fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision
Showing 1 to 25 CVEs · page 1 (more available)