CVE-2026-25223Disclosure(fastify / fastify)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify where request body validation schemas specified by Content-Type can be completely circumvented. By appending a tab character (\t) followed by arbitrary content to the Content-Type header, attackers can bypass body validation while the server still processes the body as the original content type. This issue has been patched in version 5.7.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-436CWE-179

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
fastify

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-04: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-04: 102-0302-04
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25223 Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify where request body validati… https://www.cve.org/CVERecord?id=CVE-2026-25223

    Post summary

    The post announces CVE-2026-25223, noting a validation bypass issue in Fastify before v5.7.2, without providing any PoC, exploit, or patch information.

    00010255
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25223 Fastify Content-Type Validation Bypass Vulnerability Befo... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25223 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2026-25223, a Fastify Content-Type Validation Bypass vulnerability, and links to a details page, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000050
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify-node.js-

Explore more