Описание
Denial of service in fastify
A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.
Пакеты
Наименование
fastify
npm
Затронутые версииВерсия исправления
< 2.15.1
2.15.1
Связанные уязвимости
CVSS3: 6.5
nvd
около 5 лет назад
A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.