12 Total advisories
12 Vulnerabilities
0 Malware
Dependency scanning
Check whether fastify is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.4
CVE-2026-18504
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
MEDIUM 6.1
CVE-2026-16732
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
MEDIUM 5.3
CVE-2026-3419
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
HIGH 7.5
CVE-2025-32442
Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass
HIGH 7.5
CVE-2025-32442
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header
MEDIUM 6.1
CVE-2026-3635
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
LOW 3.7
CVE-2026-25224
Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
HIGH 7.5
CVE-2026-25223
Fastify's Content-Type header tab character allows body validation bypass
MEDIUM 4.2
CVE-2022-41919
Fastify: Incorrect Content-Type parsing can lead to CSRF attack
HIGH 7.5
CVE-2022-39288
fastify vulnerable to denial of service via malicious Content-Type
UNKNOWN
CVE-2020-8192
Denial of service in fastify
HIGH 7.5
CVE-2018-3711
Denial of Service vulnerability with large JSON payloads in fastify
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes