| CVE-2026-16117 | 10 | critical | fastify / fastify\/http-proxy | Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix | 49d ago |
| CVE-2026-18248 | 9.1 | critical | fastify / fastify\/aws-lambda | @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambd | 33d ago |
| CVE-2026-14198 | 9.1 | critical | fastify / fastify\/middie | @fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matc | 66d ago |
| CVE-2026-6556 | 9.1 | critical | fastify / fastify\/express | @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path | 67d ago |
| CVE-2026-16158 | 8.7 | high | fastify / fastify\/reply-from | Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by | 49d ago |
| CVE-2026-15631 | 8.7 | high | fastify / fastify\/http-proxy | Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket | 49d ago |
| CVE-2026-18500 | 8.1 | high | fastify / fastify\/jwt | @fastify/jwt is a JSON Web Token plugin for Fastify. | 21d ago |
| CVE-2026-19474 | 7.5 | high | fastify / fastify-multipart | @fastify/multipart is a multipart form-data parser for Fastify. | 21d ago |
| CVE-2026-18549 | 7.5 | high | fastify / fastify-multipart | @fastify/multipart is a multipart form-data parser for Fastify. | 21d ago |
| CVE-2026-19484 | 7.5 | high | fastify / fastify\/busyboy | @fastify/busboy is a multipart form-data parser. | 23d ago |
| CVE-2026-19481 | 7.5 | high | fastify / fastify\/busyboy | @fastify/busboy is a multipart form-data parser. | 23d ago |
| CVE-2026-18427 | 7.5 | high | fastify / fastify-static | @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. | 30d ago |
| CVE-2026-15074 | 7.5 | high | fastify / fastify-static | @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames befo | 45d ago |
| CVE-2026-14181 | 7.5 | high | fastify / fastify\/middie | @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engin | 66d ago |
| CVE-2026-15144 | 7.3 | high | fastify / fastify\/rate-limit | @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.i | 38d ago |
| CVE-2026-3635 | 6.1 | medium | fastify / fastify | Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0 | 166d ago |