CVE-2026-33806Disclosure(fastify / fastify)

MEDIUMCVSS 7.5 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch fastify fastify systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.3.2 by the fix for CVE-2025-32442 Patches: Upgrade to fastify v5.8.5 or later. Workarounds: None. Upgrade to the patched version.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1287CWE-1289

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
fastify

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-15: 4PoC Mentioned / Linked · 2026-04-15: 2Exploit Tool / Code · 2026-04-15: 2Patch / Workaround · 2026-04-15: 3Technical Details · 2026-04-15: 404-15
Signal classification4 categories
Disclosure
125.0%
Exploit
125.0%
Patch
125.0%
PoC
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Exploit

    Fastify (25M+ downloads) reveals CVE-2026-33806. A public PoC exploit shows how a single space bypasses schema validation. Upgrade to v5.8.5 now to stay safe. #Fastify #CVE202633806 #NodeJS #CyberSecurity #Exploit #PoC #WebDev #InfoSec https://securityonline.info/fastify-cve-2026-33806-public-poc-exploit-disclosure/ https://t.co/8JnESPnsSd

    Post summary

    The post announces a public PoC exploit for CVE-2026-33806 with actionable upgrade instructions, indicating active exploitation code availability.

    05083665
    12.3K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    WebフレームワークFastifyに深刻な脆弱性。CVE-2026-33806はCVSSスコア7.5で、セキュリティ機構の迂回。Content-Typeヘッダの値先頭に半角スペースを入れると各チェックでスルーされる。バージョン5.8.5で修正。 https://securityonline.info/fastify-cve-2026-33806-public-poc-exploit-disclosure/

    Post summary

    Fastify CVE-2026-33806 (CVSS 7.5) can be exploited by adding a leading space to the Content-Type header; a public PoC exists, the issue is patched in version 5.8.5, and no active exploitation is reported.

    000211.0K
    7.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33806 Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Conten… https://www.cve.org/CVERecord?id=CVE-2026-33806

    Post summary

    The text reports a Fastify validation bypass (CVE-2026-33806) by adding a leading space, offering a technical detail but no PoC, exploit code, patch, or evidence of active exploitation.

    0000059
    57.2K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in fastify@5.8.5 just released! Patches CVE-2026-33806 — body schema validation bypass via leading space in Content-Type header https://github.com/fastify/fastify/security/advisories/GHSA-247c-9743-5963

    Post summary

    Fastify’s latest release includes a high‑severity patch for CVE‑2026‑33806, which fixes a body schema validation bypass that could be triggered by a leading space in the Content-Type header.

    00000125
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify-node.js-

Explore more