LIVE · cybersecurity feed
Live wire
vendor

Fastify

16 CVEs published in the last four months. Exploited flaws first.

Critical4
High11
Medium1
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-1611710criticalfastify\/http-proxyImpact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix49d ago
CVE-2026-141989.1criticalfastify\/middie@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matc66d ago
CVE-2026-182489.1criticalfastify\/aws-lambda@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambd33d ago
CVE-2026-65569.1criticalfastify\/express@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path67d ago
CVE-2026-156318.7highfastify\/http-proxyImpact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket49d ago
CVE-2026-161588.7highfastify\/reply-fromImpact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by49d ago
CVE-2026-185008.1highfastify\/jwt@fastify/jwt is a JSON Web Token plugin for Fastify.21d ago
CVE-2026-150747.5highfastify-static@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames befo45d ago
CVE-2026-141817.5highfastify\/middie@fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engin66d ago
CVE-2026-185497.5highfastify-multipart@fastify/multipart is a multipart form-data parser for Fastify.21d ago
CVE-2026-194747.5highfastify-multipart@fastify/multipart is a multipart form-data parser for Fastify.21d ago
CVE-2026-184277.5highfastify-static@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass.30d ago
CVE-2026-194817.5highfastify\/busyboy@fastify/busboy is a multipart form-data parser.23d ago
CVE-2026-194847.5highfastify\/busyboy@fastify/busboy is a multipart form-data parser.23d ago
CVE-2026-151447.3highfastify\/rate-limit@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.i38d ago
CVE-2026-36356.1mediumfastifySummary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0166d ago

Filter the full tracker by Fastify