CVE-2026-7768General(fastify / fastify\/accepts-serializer)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fastify fastify\/accepts-serializer systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthenticated client could send many distinct but matching Accept header variants to make the cache grow unbounded, eventually exhausting the Node.js heap and crashing the process. Versions <= 6.0.3 are affected. Update to 6.0.4 or later, which bounds the cache via an LRU with a default size of 100 entries, configurable through the new cacheSize plugin option.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/accepts-serializer

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-05-04); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
fastify\/accepts-serializer

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-05-04: 3Mentions · 2026-05-05: 1Mentions · 2026-05-08: 1Mentions · 2026-05-25: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-04: 3Technical Details · 2026-05-05: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-25: 105-0405-0505-0805-25
Signal classification3 categories
General
350.0%
Patch
233.3%
Disclosure
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-043
General2Patch1
2026-05-051
General1
2026-05-081
Disclosure1
2026-05-251
Patch1
Full discourse6 posts
  • DFIR Lab@DFIR_Lab
    Patch

    #CVSS 7.5 HIGH: CVE-2026-7768 in @fastify/accepts-serializer &lt;=6[.]0[.]3 allows remote attackers to crash Node.js via unbounded cache exhaustion. Update to 6[.]0[.]4+ immediately. #CVE #PatchNow https://t.co/rS12c9W7dY

    Post summary

    The tweet highlights a CVE-2026-7768 in Fastify's accepts-serializer, explains a CVSS 7.5 high remote DDoS via cache exhaustion, and urges users to patch to version 6.0.4 or later.

    0000043
    30 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 (Fastify), Denial of Service, #CVE-2026-7768 (High) https://dailycve.com/fastify-denial-of-service-cve-2026-7768-high/

    Post summary

    A high‑severity denial‑of‑service vulnerability (CVE‑2026‑7768) has been disclosed for Fastify, but no PoC, exploit, patch, or active exploitation is mentioned.

    0000031
    198 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7768 Denial of Service via Unbounded Cache in @fastify/accepts-serializ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7768 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post alerts about a DoS vulnerability (unbounded cache) in the fastify/accepts-serializ package, with no reference to a PoC, exploit, patch, or active exploitation.

    0000045
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-7768 @fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthenticated cli… https://www.cve.org/CVERecord?id=CVE-2026-7768 ----- Traducción: CVE-2026-7768 @fa… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-7768 and supplies technical details about the vulnerability, but provides no PoC, exploit tool, evidence of active exploitation, patch, or debunking claim.

    0000028
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7768 @fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthenticated cli… https://www.cve.org/CVERecord?id=CVE-2026-7768

    Post summary

    The post outlines a technical flaw in fastify/accepts-serializer where unbounded caching of serializer results could lead to resource exhaustion, but no PoC, exploit, patch, or exploitation evidence is provided.

    00000207
    57.4K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in @fastify/accepts-serializer@6.0.4 just released! Patches CVE-2026-7768 — vulnerable to Denial of Service via Unbounded Accept Header Cache Growth https://github.com/fastify/fastify-accepts-serializer/security/advisories/GHSA-qxhc-wx3p-2wmg

    Post summary

    The post announces a high‑severity patch for CVE‑2026‑7768, detailing a denial‑of‑service flaw caused by unbounded Accept Header cache growth.

    00000143
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/accepts-serializer-node.js-

Explore more