CVE-2026-18504Patch(fastify / fastify)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch fastify fastify systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a request body schema targets a root primitive value. When the schema validates a top-level primitive such as an integer, Ajv can coerce a JSON string into the expected type during validation, but Fastify does not replace the root request body with the coerced value, so the route handler receives the original unvalidated string. As a result, a request that should have failed validation can reach application logic with a value that does not satisfy the schema, which can undermine integrity and access-control checks that rely on the validated type. Users should upgrade to fastify 5.12.1, which fixes the mismatch. No known workarounds are available.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-08-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
fastify

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-18: 1Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-19: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-19: 108-1808-19
Signal classification2 categories
Patch
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-181
Patch1
2026-08-191
PoC1
Full discourse2 posts
  • ExploitGrid@exploitgrid
    PoC

    Top CVEs w/ public exploits (Aug 19): CVE-2026-19500 SureForms contains an uncontrolled resource con... CVE-2026-16732 fastify vulnerable to X-Forwarded-* spoofing un... CVE-2026-18504 fastify vulnerable to schema validation bypass ... Protect via https://exploitgrid.net

    Post summary

    The post lists three CVEs that have publicly available exploits, referencing exploitgrid.net for protection, but it does not supply specific exploit code or evidence of active attacks.

    0100049
    35 followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in fastify@5.12.1 just released! Patches CVE-2026-18504. fastify vulnerable to schema validation bypass via root primitive coercion mismatch. https://github.com/fastify/fastify/security/advisories/GHSA-w2qp-rph6-63g4

    Post summary

    Fastify 5.12.1 includes a patch for CVE-2026-18504, fixing a schema validation bypass involving root primitive coercion mismatches.

    00010237
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify-node.js-

Explore more