Fastify Fixed Four Ways Requests Can Bypass Route Checks
Fastify 5.12.2 patched four High-severity issues on 4 September 2026. Later database review is a catch-up trigger, not a new disclosure. The relevant question is which routes use the affected patterns.
- CVE-2026-76169: a malformed URL could reach a sibling plugin’s protected not-found handler, skipping its
preHandlerand globalonRequest. The affected range is 4.0.0 to before 5.12.2. - CVE-2026-84469: a boolean
falserequest schema could be treated as absent, allowing the handler to run. - CVE-2026-84428: header dependencies could be skipped through incomplete case normalisation. External shared
$refheader schemas registered withaddSchemaremain outside the fix;FSTSEC002warns, and the vendor advises an inline schema. - CVE-2026-84504: with an
$asyncrequest schema, a root-levelvalueproperty could replace the validated request part seen by the handler. The latter three advisories list versions before 5.12.2.
Make the patch decision reviewable
BlackTree analysis: Collect the deployed version and route map; prioritise private or privileged handlers. Upgrade affected services to 5.12.2. A 4.x deployment needs a supported migration or fix decision. In controlled tests, prove rejection for each pattern present. For $async, include a benign root-level value and confirm the handler receives the unchanged body. Review FSTSEC002. Save the test result and build identity; an ordinary success does not test the boundary.


