Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
RSS Feed
LOW
GHSA-mrq3-vjjr-p77c
CVE-2026-25224
Description:
Impact
A Denial of Service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applications that return a ReadableStream (or Response with a Web Stream body) via reply.send() are impacted. A slow or non-reading client can trigger unbounded buffering when backpressure is ignored, leading to process crashes or severe degradation.
Patches
The issue is fixed in Fastify 5.7.3. Users should upgrade to 5.7.3 or later.
Workarounds
Avoid sending Web Streams from Fastify responses (e.g., ReadableStream or Response bodies). Use Node.js streams (stream.Readable) or buffered payloads instead until the project can upgrade.
References
Affected Packages
| Ecosystem | Package | Vulnerable Versions | Patched Version |
|---|---|---|---|
| npm |
fastify
|
<= 5.7.2 |
5.7.3
|
chore(deps): bump fastify from 4.29.1 to 5.7.4 in /services/attestation in the npm_and_yarn group across 1 directory
Closed 3 months ago
NethermindEth/aztec-fpc #211
npm:fastify
chore(deps): bump the npm_and_yarn group across 10 directories with 11 updates
Closed 3 months ago
prakashgbid/caia #27
npm:@angular/core
npm:axios
+7 more
Bump the npm_and_yarn group across 12 directories with 18 updates
Closed 3 months ago
ANT0071/activepieces #26
npm:axios
npm:webpack
+16 more
chore(deps): bump the npm_and_yarn group across 13 directories with 18 updates
Open 3 months ago
UniversalStandards/activepieces #27
npm:axios
npm:webpack
+16 more
Bump the npm_and_yarn group across 12 directories with 18 updates
Closed 3 months ago
balajirajput96/activepieces #27
npm:axios
npm:webpack
+16 more
Bump the npm_and_yarn group across 34 directories with 13 updates
Closed 3 months ago
ar27111994/DefinitelyTyped #10
npm:axios
npm:electron
+1 more
chore(deps): bump the npm_and_yarn group across 3 directories with 9 updates
Closed 3 months ago
nrasslimy/openai-agents-js #7
npm:next
npm:diff
+7 more
Bump the npm_and_yarn group across 12 directories with 18 updates
Open 3 months ago
balajirajput96/activepieces #25
npm:axios
npm:webpack
+16 more
chore(deps): bump the npm_and_yarn group across 10 directories with 13 updates
Open 3 months ago
prakashgbid/caia #26
npm:@angular/core
npm:axios
+9 more
Bump the npm_and_yarn group across 14 directories with 21 updates
Open 3 months ago
GlacierEQ/activepieces #26
npm:axios
npm:tar-fs
+18 more
chore(deps): bump the npm_and_yarn group across 13 directories with 17 updates
Closed 3 months ago
sizzlebop/activepieces #24
npm:axios
npm:webpack
+15 more
Bump the npm_and_yarn group across 12 directories with 18 updates
Closed 3 months ago
ANT0071/activepieces #24
npm:axios
npm:webpack
+16 more
Bump the npm_and_yarn group across 14 directories with 20 updates
Open 3 months ago
GlacierEQ/activepieces #25
npm:axios
npm:tar-fs
+17 more
chore(deps): bump the npm_and_yarn group across 10 directories with 14 updates
Open 3 months ago
prakashgbid/caia #25
npm:@angular/core
npm:axios
+10 more
Bump the npm_and_yarn group across 16 directories with 16 updates
Open 3 months ago
CaffeeLake/bun #184
npm:axios
npm:webpack
+6 more
Bump the npm_and_yarn group across 6 directories with 10 updates
Open 3 months ago
shinzai-dev/misskey-tempura #1
npm:storybook
npm:rollup
+7 more
chore(deps): bump the dependencies group across 1 directory with 18 updates
Open 3 months ago
karant-dev/AutoRedact #61
npm:@vitejs/plugin-react
npm:globals
+15 more
Bump the npm_and_yarn group across 14 directories with 19 updates
Closed 3 months ago
GlacierEQ/activepieces #24
npm:axios
npm:tar-fs
+16 more
chore(deps): bump the npm_and_yarn group across 13 directories with 16 updates
Open 3 months ago
UniversalStandards/activepieces #24
npm:axios
npm:webpack
+14 more
chore(deps): bump the npm_and_yarn group across 10 directories with 13 updates
Closed 3 months ago
prakashgbid/caia #23
npm:@angular/core
npm:axios
+9 more
Bump the npm_and_yarn group across 14 directories with 18 updates
Open 3 months ago
GlacierEQ/activepieces #23
npm:axios
npm:tar-fs
+15 more
chore(deps): bump the npm_and_yarn group across 4 directories with 13 updates
Closed 3 months ago
ccwu0918/ChatGPT-Admin-Web #5
npm:vitest
npm:vite
+6 more
chore(deps): bump the npm_and_yarn group across 10 directories with 13 updates
Open 3 months ago
prakashgbid/caia #22
npm:@angular/core
npm:axios
+9 more
Bump fastify from 4.29.1 to 5.7.3 in /Javascript/vitaldemo
Closed 3 months ago
vitaldb/vitalutils #8
npm:fastify
chore(deps): bump the npm_and_yarn group across 2 directories with 18 updates
Closed 3 months ago
trizist/platformatic #8
npm:astro
npm:vite
+11 more
chore(deps): bump fastify from 4.29.1 to 5.7.4
Open 3 months ago
mohit-kumar33/skill_era #3
npm:fastify
chore(deps): bump the npm_and_yarn group across 1 directory with 4 updates
Closed 3 months ago
Bang2985/agents #97
npm:undici
npm:rollup
+2 more
chore(deps): bump the npm_and_yarn group across 10 directories with 13 updates
Closed 3 months ago
prakashgbid/caia #20
npm:@angular/core
npm:axios
+9 more
chore(deps): bump the npm_and_yarn group across 5 directories with 15 updates
Closed 3 months ago
passariello/jan #14
npm:axios
npm:next
+9 more
Bump the npm_and_yarn group across 14 directories with 18 updates
Open 3 months ago
GlacierEQ/activepieces #20
npm:axios
npm:tar-fs
+14 more
Bump the npm_and_yarn group across 16 directories with 14 updates
Closed 3 months ago
ssushant0011/bun #27
npm:axios
npm:webpack
+6 more
Bump the npm_and_yarn group across 2 directories with 2 updates
Closed 3 months ago
AKJUS/DefinitelyTyped-1 #186
npm:svelte
npm:fastify
chore(deps): bump the npm_and_yarn group across 2 directories with 2 updates
Open 3 months ago
aiob3/llm-readable-kit #4
npm:rollup
npm:fastify
chore(deps): bump the npm_and_yarn group across 2 directories with 8 updates
Closed 3 months ago
trizist/vitest #10
npm:axios
npm:vite
+5 more
Bump the npm_and_yarn group across 18 directories with 21 updates
Open 3 months ago
GlacierEQ/activepieces #18
npm:axios
npm:tar-fs
+16 more
Bump the npm_and_yarn group across 2 directories with 2 updates
Closed 3 months ago
slidebolt/ui #1
npm:fastify
npm:@fastify/session
chore(deps): bump the npm_and_yarn group across 5 directories with 10 updates
Closed 3 months ago
momoirodouhu/misskey #5
npm:storybook
npm:tar
+5 more
Bump the npm_and_yarn group across 5 directories with 7 updates
Closed 3 months ago
khulnasoft/khulnasoft-lsp #4
npm:vite
npm:fast-xml-parser
+3 more
chore(deps): bump the npm_and_yarn group across 13 directories with 18 updates
Open 3 months ago
UniversalStandards/activepieces #20
npm:react-router
npm:axios
+16 more
chore(deps): bump the npm_and_yarn group across 3 directories with 11 updates
Open 3 months ago
balajirajput96/openai-agents-js #6
npm:astro
npm:vite
+4 more
chore(deps): bump the npm_and_yarn group across 2 directories with 18 updates
Closed 3 months ago
trizist/platformatic #7
npm:astro
npm:vite
+11 more
chore(deps): bump the npm_and_yarn group across 1 directory with 4 updates
Closed 3 months ago
Bang2985/agents #91
npm:tar-fs
npm:undici
+2 more
chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates
Closed 3 months ago
Bang2985/agents #90
npm:undici
npm:rollup
+1 more
chore(deps): bump the npm_and_yarn group across 10 directories with 17 updates
Open 3 months ago
prakashgbid/caia #18
npm:@angular/core
npm:axios
+13 more
Bump the npm_and_yarn group across 12 directories with 16 updates
Closed 3 months ago
khulnasoft/BenchWeb #44
npm:fastify
npm:@nestjs/core
+4 more
chore(deps): bump the npm_and_yarn group across 2 directories with 17 updates
Closed 3 months ago
trizist/platformatic #6
npm:astro
npm:vite
+11 more
Bump the npm_and_yarn group across 12 directories with 19 updates
Open 3 months ago
balajirajput96/activepieces #18
npm:react-router
npm:axios
+17 more
Bump the npm_and_yarn group across 34 directories with 9 updates
Closed 3 months ago
lkoskela/DefinitelyTyped #23
npm:axios
npm:electron
+2 more
Bump the npm_and_yarn group across 3 directories with 3 updates
Closed 3 months ago
Upper-Echalon/DefinitelyTyped #966
npm:rollup
npm:svelte
+1 more
Bump the npm_and_yarn group across 13 directories with 20 updates
Open 3 months ago
JoftheV/helium-program-library #10
npm:axios
npm:tar-fs
+18 more
Actions
Advisory Details
| Published: | February 02, 2026 4 months ago |
| Updated: | June 07, 2026 about 6 hours ago |
| CVSS Score: | 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
| EPSS: | 0.02% 6th percentile |
| Source: | Github |
| Classification: | GENERAL |
| UUID: | GSA_kwCzR0hTQS1tcnEzLXZqanItcDc3Y84ABRz5 |
PR Statistics
PR Status
Open
199 (51.3%)
Merged
0 (0.0%)
Closed
189 (48.7%)
Update Types
Major
379 (17.9%)
Minor
1022 (48.3%)
Patch
713 (33.7%)