<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Fastify (&lt; 5.12.2, &lt; 6.0.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/fastify--5.12.2--6.0.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 04:21:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/fastify--5.12.2--6.0.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Fastify Request Body Replacement Vulnerability via Async Validation Result</title><link>https://feed.craftedsignal.io/briefs/2026-10-fastify-validation-collision/</link><pubDate>Thu, 01 Oct 2026 04:21:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fastify-validation-collision/</guid><description>A vulnerability in Fastify's request validation logic (CVE-2026-84504) allows attackers to perform request body replacement when using $async JSON schema validators, leading to potential unauthorized state changes or data disclosure.</description><content:encoded><![CDATA[<p>Fastify suffers from a validation logic flaw (CVE-2026-84504) where the framework incorrectly processes results from asynchronous JSON schema validators. The framework is designed to unwrap results shaped like <code>{ value, error }</code> to support synchronous custom compilers, where the <code>value</code> replaces the request part and <code>error</code> triggers a failure. However, $async validators in JSON schema resolve to the validated data itself. Fastify incorrectly applied the same unwrapping logic to these asynchronous results.</p>
<p>If a request body processed by an $async schema contains a top-level <code>value</code> property, Fastify replaces the entire request part with that nested value before the application handler executes. An attacker can manipulate this behavior by crafting a payload containing controlled <code>value</code> or <code>error</code> properties, effectively bypassing the intended schema validation. This allows attackers to submit payloads that the application incorrectly believes have been validated, potentially leading to unauthorized state changes or information disclosure if the backend logic relies on the integrity of the schema-validated object.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects applications built with Fastify versions prior to 5.12.2 and 6.0.0 that utilize $async request schemas. Successful exploitation allows an attacker to bypass data validation controls, potentially resulting in unauthorized administrative actions, privilege escalation, or unauthorized access to sensitive application data depending on the specific implementation of the endpoint logic.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Fastify to version 5.12.2 or 6.0.0 immediately to apply the patch which prevents asynchronous validation results from triggering request part replacement.</li>
<li>Audit existing routes to identify those utilizing $async request schemas and perform secondary validation within 'onRequest' or 'preHandler' hooks as a temporary mitigation.</li>
<li>Refactor custom async validator compilers to signal failure by rejecting or throwing an exception, rather than returning an <code>{ error }</code> object, until a full patch is applied.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>vulnerability</category><category>cve</category><category>authentication-bypass</category><category>security-bypass</category><category>cve-2026-84428</category></item></channel></rss>