BlackTree Security · Infrastructure · Automation · AI

Fastify Fixed Four Ways Requests Can Bypass Route Checks

Fastify 5.12.2 patched four High-severity issues on 4 September 2026. Later database review is a catch-up trigger, not a new disclosure. The relevant question is which routes use the affected patterns.

  • CVE-2026-76169: a malformed URL could reach a sibling plugin’s protected not-found handler, skipping its preHandler and global onRequest. The affected range is 4.0.0 to before 5.12.2.
  • CVE-2026-84469: a boolean false request schema could be treated as absent, allowing the handler to run.
  • CVE-2026-84428: header dependencies could be skipped through incomplete case normalisation. External shared $ref header schemas registered with addSchema remain outside the fix; FSTSEC002 warns, and the vendor advises an inline schema.
  • CVE-2026-84504: with an $async request schema, a root-level value property could replace the validated request part seen by the handler. The latter three advisories list versions before 5.12.2.

Make the patch decision reviewable

BlackTree analysis: Collect the deployed version and route map; prioritise private or privileged handlers. Upgrade affected services to 5.12.2. A 4.x deployment needs a supported migration or fix decision. In controlled tests, prove rejection for each pattern present. For $async, include a benign root-level value and confirm the handler receives the unchanged body. Review FSTSEC002. Save the test result and build identity; an ordinary success does not test the boundary.

Sources

  • Release and advisories A, B, C, D, all dated 4 September 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *