CVE-2026-25223
Last modified
CVE-2026-25223 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify where request body validation schemas specified by Content-Type can be completely circumvented. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify where request body validation schemas specified by Content-Type can be completely circumvented. By appending a tab character (\t) followed by arbitrary content to the Content-Type header, attackers can bypass body validation while the server still processes the body as the original content type. This issue has been patched in version 5.7.2.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fastify | Fastify | < 5.7.2 |
References
- https://fastify.dev/docs/latest/Reference/Validation-and-SerializationProduct, Technical Description
- https://github.com/fastify/fastify/security/advisories/GHSA-jx2c-rxcm-jvmqMitigation, Vendor Advisory
- https://hackerone.com/reports/3464114Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-25223?
How severe is CVE-2026-25223?
How do I fix CVE-2026-25223?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-25212An issue was discovered in Percona PMM before 3.7. Because a…9.9
- CVE-2026-25219The `access_key` and `connection_string` connection properti…6.5
- CVE-2026-2522A security vulnerability has been detected in Open5GS up to …9.8
- CVE-2026-25220OpenEMR is a free and open source electronic health records …6.5
- CVE-2026-25221PolarLearn is a free and open-source learning program. In 0-…8.1
- CVE-2026-25222PolarLearn is a free and open-source learning program. In 0-…7.5
- CVE-2026-25224Fastify is a fast and low overhead web framework, for Node.j…3.7
- CVE-2026-25227authentik is an open-source identity provider. From 2021.3.1…7.2
- CVE-2026-25228Signal K Server is a server application that runs on a centr…4.3
- CVE-2026-25229Gogs is an open source self-hosted Git service. Versions 0.1…6.5
- CVE-2026-2523A vulnerability was detected in Open5GS up to 2.7.6. The aff…7.5
- CVE-2026-25230FileRise is a self-hosted web file manager / WebDAV server. …5.4
Are you affected by CVE-2026-25223?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
