{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fastify--5.12.2--6.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fastify:fastify:*:*:*:*:*:*:*:*","cpe:2.3:a:fastify:fastify:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-84504"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["fastify (\u003c 5.12.2)","Fastify (\u003c 5.12.2, \u003c 6.0.0)"],"_cs_severities":["high"],"_cs_tags":["web-application","vulnerability","cve","authentication-bypass","security-bypass","cve-2026-84428"],"_cs_type":"advisory","_cs_vendors":["Fastify"],"content_html":"\u003cp\u003eFastify suffers from a validation logic flaw (CVE-2026-84504) where the framework incorrectly processes results from asynchronous JSON schema validators. The framework is designed to unwrap results shaped like \u003ccode\u003e{ value, error }\u003c/code\u003e to support synchronous custom compilers, where the \u003ccode\u003evalue\u003c/code\u003e replaces the request part and \u003ccode\u003eerror\u003c/code\u003e triggers a failure. However, $async validators in JSON schema resolve to the validated data itself. Fastify incorrectly applied the same unwrapping logic to these asynchronous results.\u003c/p\u003e\n\u003cp\u003eIf a request body processed by an $async schema contains a top-level \u003ccode\u003evalue\u003c/code\u003e property, Fastify replaces the entire request part with that nested value before the application handler executes. An attacker can manipulate this behavior by crafting a payload containing controlled \u003ccode\u003evalue\u003c/code\u003e or \u003ccode\u003eerror\u003c/code\u003e properties, effectively bypassing the intended schema validation. This allows attackers to submit payloads that the application incorrectly believes have been validated, potentially leading to unauthorized state changes or information disclosure if the backend logic relies on the integrity of the schema-validated object.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects applications built with Fastify versions prior to 5.12.2 and 6.0.0 that utilize $async request schemas. Successful exploitation allows an attacker to bypass data validation controls, potentially resulting in unauthorized administrative actions, privilege escalation, or unauthorized access to sensitive application data depending on the specific implementation of the endpoint logic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Fastify to version 5.12.2 or 6.0.0 immediately to apply the patch which prevents asynchronous validation results from triggering request part replacement.\u003c/li\u003e\n\u003cli\u003eAudit existing routes to identify those utilizing $async request schemas and perform secondary validation within 'onRequest' or 'preHandler' hooks as a temporary mitigation.\u003c/li\u003e\n\u003cli\u003eRefactor custom async validator compilers to signal failure by rejecting or throwing an exception, rather than returning an \u003ccode\u003e{ error }\u003c/code\u003e object, until a full patch is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T04:21:22Z","date_published":"2026-10-01T04:21:02Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fastify-validation-collision/","summary":"A vulnerability in Fastify's request validation logic (CVE-2026-84504) allows attackers to perform request body replacement when using $async JSON schema validators, leading to potential unauthorized state changes or data disclosure.","title":"Fastify Request Body Replacement Vulnerability via Async Validation Result","url":"https://feed.craftedsignal.io/briefs/2026-10-fastify-validation-collision/"}],"language":"en","title":"CraftedSignal Threat Feed - Fastify (\u003c 5.12.2, \u003c 6.0.0)","version":"https://jsonfeed.org/version/1.1"}