Количество 4
Количество 4
CVE-2026-33806
Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.3.2 by the fix for CVE-2025-32442 Patches: Upgrade to fastify v5.8.5 or later. Workarounds: None. Upgrade to the patched version.
CVE-2026-33806
Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.3.2 by the fix for CVE-2025-32442 Patches: Upgrade to fastify v5.8.5 or later. Workarounds: None. Upgrade to the patched version.
GHSA-247c-9743-5963
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header
BDU:2026-09015
Уязвимость фреймворка Fastify программной платформы Node.js, связанная с неправильной проверкой указанного типа входных данных, позволяющая нарушителю обойти существующие механизмы защиты
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33806 Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.3.2 by the fix for CVE-2025-32442 Patches: Upgrade to fastify v5.8.5 or later. Workarounds: None. Upgrade to the patched version. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-33806 Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.3.2 by the fix for CVE-2025-32442 Patches: Upgrade to fastify v5.8.5 or later. Workarounds: None. Upgrade to the patched version. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-247c-9743-5963 Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
BDU:2026-09015 Уязвимость фреймворка Fastify программной платформы Node.js, связанная с неправильной проверкой указанного типа входных данных, позволяющая нарушителю обойти существующие механизмы защиты | CVSS3: 7.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу