Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.58% | — | Fastify StaticAI | 17/9/2026 | 18/9/2026 | @fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume, a route guard or allowedPath restriction can be bypassed by altering the letter case of a path segment. The route… | |
| Pendiente de análisis | Crítica (9.1) | 0.33% | — | Fastify Proxy-addrAI | 16/9/2026 | 17/9/2026 | @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the… | |
| Pendiente de análisis | Alta (8.1) | 0.47% | — | Fastify AuthAI | 16/9/2026 | 17/9/2026 | @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the run "all" option and one entry is a nested array acting as an AND group, the… | |
| Pendiente de análisis | Media (5.9) | 0.41% | — | FastifyAI | 16/9/2026 | 16/9/2026 | fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fastify unconditionally sets the Transfer-Encoding: chunked header, which is forbidden on HTTP/2, so Node.js throws while serializing the… | |
| Pendiente de análisis | Media (4.8) | 0.25% | — | FastifyAIOpenjsf Fast-uriAIAjv.js AJVAI | 15/9/2026 | 16/9/2026 | fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved names to, subject, and body while the name is still percent-encoded, and decodes it… | |
| Pendiente de análisis | Alta (8.1) | 0.70% | — | Fastify-cliAI | 8/9/2026 | 8/9/2026 | fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging interface can be exposed beyond the local machine, and because the Inspector… | |
| Analizada | Alta (7.5) | 0.52% | — | Fastify | 4/9/2026 | 15/9/2026 | fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level required array, and does not lowercase the trigger and dependent… | |
| Analizada | Crítica (9.1) | 0.52% | — | Fastify/middie | 4/9/2026 | 15/9/2026 | @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different strings, a request using an… | |
| Analizada | Alta (8.1) | 0.43% | — | Fastify | 4/9/2026 | 15/9/2026 | fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request body with that property's value before… | |
| Analizada | Alta (7.5) | 0.49% | — | Fastify | 4/9/2026 | 15/9/2026 | fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's body, querystring, params, or headers schema to deny all input,… | |
| Analizada | Alta (7.5) | 0.53% | — | Fastify | 4/9/2026 | 15/9/2026 | fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths… | |
| Analizada | Alta (7.5) | 0.74% | — | Fastify/http-proxy | 3/9/2026 | 9/9/2026 | @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects… | |
| Analizada | Media (5.8) | 0.33% | — | Fastify/busyboy | 21/8/2026 | 8/9/2026 | @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return line-feed sequence, so a lone carriage return or line feed embedded in a part header is not treated as a line break and is carried verbatim into the parsed… | |
| Analizada | Media (5.3) | 0.31% | — | Fastify | 18/8/2026 | 2/9/2026 | fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a request body schema targets a root primitive value. When the schema validates a top-level primitive such as an integer, Ajv can coerce a JSON string into the expected type… | |
| Analizada | Media (6.1) | 0.16% | — | Fastify | 18/8/2026 | 2/9/2026 | fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host, protocol, hostname, ip, and ips values, checking the connecting address. That guard closes the IP, CIDR, and custom-function forms of trustProxy… | |
| Analizada | Alta (7.5) | 0.49% | — | Fastify-multipart | 15/8/2026 | 2/9/2026 | @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing between multipart parts. The iterator rejection that occurs between parts… | |
| Analizada | Alta (7.5) | 0.60% | — | Fastify-multipart | 15/8/2026 | 2/9/2026 | @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the client then aborts the connection before… | |
| Analizada | Alta (8.1) | 0.26% | — | Fastify/jwt | 15/8/2026 | 4/9/2026 | @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's globally configured secret, because the option merge applies the global key last. Applications that use different keys for different… | |
| Analizada | Media (5.4) | 0.10% | — | Fastify/oauth2 | 15/8/2026 | 4/9/2026 | @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-side binding to the browser that began the… | |
| Analizada | Alta (7.5) | 0.61% | — | Fastify/busyboy | 13/8/2026 | 3/9/2026 | @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry byte array, and a… | |
| Analizada | Alta (7.5) | 0.49% | — | Fastify/busyboy | 13/8/2026 | 3/9/2026 | @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript… | |
| Analizada | Alta (7.5) | 0.66% | — | Fastify-static | 6/8/2026 | 4/9/2026 | @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer.… | |
| Analizada | Crítica (9.1) | 0.38% | — | Fastify/aws-lambda | 3/8/2026 | 4/9/2026 | @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the getter that populates this decoration… | |
| Analizada | Media (5.3) | 0.40% | — | Fastify/rate-limit | 29/7/2026 | 5/8/2026 | @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can control a large address range (a /64 holds 2^64 distinct addresses) and the same address has multiple valid textual representations, an IPv6 capable client can defeat… | |
| Analizada | Media (5.3) | 0.32% | — | Fastify/forwarded | 29/7/2026 | 5/8/2026 | @fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or more comma separated entries, the parser trims only space characters and does not strip horizontal tabs, even though RFC 7230 defines optional whitespace as both space and tab. As a… |