An open index of dependabot pull requests across open source projects.

fastify

Ecosystem:
npm
Package URL:
pkg:npm/fastify
Total PRs:
3,367 Dependabot PRs
Latest PR:
4 days ago
Unique Repositories:
1,315 repositories
Unique Repos (30 days):
22 repositories
Security Advisories
Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass
GHSA-mg2h-6x62-wpwc CVE-2025-32442 HIGH published over 1 year ago • updated 5 days ago
### Impact In applications that specify different validation strategies for different content types, it's possible to bypass the validation by pro...
Fastify's Content-Type header tab character allows body validation bypass
GHSA-jx2c-rxcm-jvmq CVE-2026-25223 HIGH published 6 months ago • updated 14 days ago
### Impact A validation bypass vulnerability exists in Fastify where request body validation schemas specified by Content-Type can be completely c...
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
GHSA-444r-cwp2-x5xf CVE-2026-3635 MODERATE published 4 months ago • updated 26 days ago
## Summary When `trustProxy` is configured with a restrictive trust function (e.g., a specific IP like `trustProxy: '10.0.0.1'`, a subnet, a hop c...
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
GHSA-573f-x89g-hqp9 CVE-2026-3419 MODERATE published 5 months ago • updated 9 days ago
# Description Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in violation of...
Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
GHSA-mrq3-vjjr-p77c CVE-2026-25224 LOW published 6 months ago • updated 23 days ago
### Impact A Denial of Service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applica...
Recent PRs
Bump fastify from 5.8.5 to 5.9.0

123jimin/stelaro #11

5.8.5 → 5.9.0 Minor PR
Closed about 1 month ago 1 comment
123jimin
Package Details
Name: fastify
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/fastify
JSON API: View JSON
Security Advisories

10

Active advisories
HIGH 5
MODERATE 4
LOW 1
View All npm Advisories
Package Information
Description:

Fast and low overhead web framework, for Node.js

Repository: https://github.com/fastify/fastify
Homepage: https://fastify.dev/
Latest Release: 5.3.3
about 1 year ago
Dependent Repos: 16,712
Dependent Packages: 3,270
Downloads: 10,856,076
Ranking: Top 0.206% by dependent repos Top 0.1136% by downloads Top 0.0251% by dependent pkgs
PR Status
Open 1,573 (46.7%)
Merged 308 (9.1%)
Closed 1,278 (38.0%)
PR Types
Major 652 (19.4%)
Minor 1,711 (50.8%)
Patch 754 (22.4%)
Removal 36 (1.1%)