UNKNOWN npm
Denial of service in fastify
GHSA-xw5p-hw6r-2j98 · CVE-2020-8192
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.
Ready to move
Start Securing
Free, no credit card | First findings in minutes