Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33806

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.3.2 by the fix for CVE-2025-32442 Patches: Upgrade to fastify v5.8.5 or later. Workarounds: None. Upgrade to the patched version.

A flaw was found in Fastify. A remote attacker could exploit this vulnerability by prepending a space to the Content-Type header in a request. This action bypasses the application's schema validation, allowing the attacker to submit data that would otherwise be rejected. This could lead to unexpected data processing and potential integrity issues within the application.

Отчет

This vulnerability doesn't affect any supported Red Hat product. This happens because or either the vulnerability was introduced in a version later than the shipped one or the product is already shipping a patched version of Fastify.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-dashboard-rhel8Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-dashboard-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-gen-ai-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-maas-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-model-registry-rhel9Not affected
Red Hat OpenShift Dev Spacesdevspaces/dashboard-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1289
https://bugzilla.redhat.com/show_bug.cgi?id=2458596fastify: Fastify: Schema validation bypass via malformed Content-Type header

EPSS

Процентиль: 33%
0.00408
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.3.2 by the fix for CVE-2025-32442 Patches: Upgrade to fastify v5.8.5 or later. Workarounds: None. Upgrade to the patched version.

CVSS3: 7.5
github
4 месяца назад

Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость фреймворка Fastify программной платформы Node.js, связанная с неправильной проверкой указанного типа входных данных, позволяющая нарушителю обойти существующие механизмы защиты

EPSS

Процентиль: 33%
0.00408
Низкий

7.5 High

CVSS3