Vulnerabilities
Vulnerable Software
Fastify:  >> Fastify  >> 0.19.0  Security Vulnerabilities
fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of service via malicious use of the Content-Type header. An attacker can send an invalid Content-Type header that can cause the application to crash. This issue has been addressed in commit `fbb07e8d` and will be included in release version 4.8.1. Users are advised to upgrade. Users unable to upgrade may manually filter out http content with malicious Content-Type headers.
CVSS Score
7.5
EPSS Score
0.1
Published
2022-10-10
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.
CVSS Score
7.5
EPSS Score
0.008
Published
2018-06-07


Contact Us

Shodan ® - All rights reserved