CVE-2026-3419Disclosure(fastify / fastify)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fastify fastify systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in violation of RFC 9110 §8.3.1(https://httpwg.org/specs/rfc9110.html#field.content-type). For example, a request sent with Content-Type: application/json garbage passes validation and is processed normally, rather than being rejected with 415 Unsupported Media Type. When regex-based content-type parsers are in use (a documented Fastify feature), the malformed value is matched against registered parsers using the full string including the trailing garbage. This means a request with an invalid content-type may be routed to and processed by a parser it should never have reached. Impact: An attacker can send requests with RFC-invalid Content-Type headers that bypass validity checks, reach content-type parser matching, and be processed by the server. Requests that should be rejected at the validation stage are instead handled as if the content-type were valid. Workarounds: Deploy a WAF rule to protect against this Fix: The fix is available starting with v5.8.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-185

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Disclose: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-06); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
fastify

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-06: 4Mentions · 2026-03-13: 1Patch / Workaround · 2026-03-06: 2Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-06: 403-0603-13
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
Disclose
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-064
Disclosure2Patch2
2026-03-131
Disclose1
Full discourse5 posts
  • Saad Fellahi@SaadFellahii
    Disclose

    Finally my first CVEs. Hono.js (v4.12.4) • CVE-2026-29086 • CVE-2026-29085 Fastify (v5.8.1) • CVE-2026-3419 Shoutout to @honojs & @fastifyjs for the quick fixes. Write-ups on the exploit chains coming soon. #AppSec #NodeJS #CVE #BugBounty https://t.co/wLne1JffJS

    Post summary

    The tweet announces the writer’s first discovered CVEs for Hono.js and Fastify, noting that vendors have released quick fixes and that detailed write‑ups on exploit chains are forthcoming.

    1002165
    42 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3419 Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in violation of RFC 9110 §8.3.1(https://httpwg.org/… https://www.cve.org/CVERecord?id=CVE-2026-3419

    Post summary

    The advisory highlights that Fastify accepts improperly formatted Content-Type headers, violating RFC 9110, without providing PoC, exploit, or patch details.

    0000091
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3419 - Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation Intel Report: https://ift.tt/I6NzVrS

    Post summary

    The tweet announces CVE-2026-3419 in Fastify, detailing a missing end anchor that permits malformed Content-Types to bypass validation, with no PoC, exploit, patch, or active exploitation evidence provided.

    0000021
    343 followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-3419: Fastify before 5.8.1 accepts malformed Content-Type headers, letting invalid requests sneak past validation and hit your handlers. Patch now or block bad headers at the edge. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-3419 #Fastify #NodeJS #infosec

    Post summary

    Fastify versions before 5.8.1 are affected by malformed Content-Type header injections that bypass validation; applying the latest patch or blocking bad headers at the edge mitigates the risk.

    0000038
    51 followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Moderate-severity security fix in fastify@5.8.1 just released! Patches CVE-2026-3419 — Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation https://github.com/fastify/fastify/security/advisories/GHSA-573f-x89g-hqp9

    Post summary

    Fastify has released a moderate‑severity patch for CVE‑2026‑3419, addressing a missing end‑anchor in subtypeNameReg that allows malformed content‑types to slip through validation.

    00000142
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify-node.js-

Explore more