An open index of dependabot pull requests across open source projects.

fastify

Ecosystem:
npm
Package URL:
pkg:npm/fastify
Total PRs:
1,383 Dependabot PRs
Latest PR:
about 8 hours ago
Unique Repositories:
533 repositories
Unique Repos (30 days):
230 repositories
Security Advisories
Denial of service in fastify
GHSA-xw5p-hw6r-2j98 CVE-2020-8192 MODERATE published about 5 years ago • updated 29 days ago
A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the a...
Denial of Service vulnerability with large JSON payloads in fastify
GHSA-mq6c-fh97-4gwv CVE-2018-3711 HIGH published about 7 years ago • updated about 1 month ago
Affected versions of `fastify` are vulnerable to a denial of service when processing a request with `Content-Type` set to `application/json` and a ...
Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass
GHSA-mg2h-6x62-wpwc CVE-2025-32442 HIGH published 5 months ago • updated 19 days ago
### Impact In applications that specify different validation strategies for different content types, it's possible to bypass the validation by pro...
Fastify: Incorrect Content-Type parsing can lead to CSRF attack
GHSA-3fjj-p79j-c9hh CVE-2022-41919 MODERATE published almost 3 years ago • updated 19 days ago
### Impact The attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight` checking of `fetch`. `fetch()` requests with Content-Type’...
fastify vulnerable to denial of service via malicious Content-Type
GHSA-455w-c45v-86rg CVE-2022-39288 HIGH published almost 3 years ago • updated about 1 month ago
### Impact An attacker can send an invalid `Content-Type` header that can cause the application to crash, leading to a possible Denial of Service a...
Recent PRs
Bump fastify from 4.29.1 to 5.6.0

HackerRoy221/aniapi #8

4.29.1 → 5.6.0 Major PR
Open about 21 hours ago 1 comment
HackerRoy221
Bump fastify from 4.29.1 to 5.6.0

zsecre/anime-vercel2 #8

4.29.1 → 5.6.0 Major PR
Open about 21 hours ago 1 comment
zsecre
Package Details
Name: fastify
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/fastify
JSON API: View JSON
Security Advisories

5

Active advisories
HIGH 3
MODERATE 2
View All npm Advisories
Package Information
Description:

Fast and low overhead web framework, for Node.js

Repository: https://github.com/fastify/fastify
Homepage: https://fastify.dev/
Latest Release: 5.3.3
4 months ago
Dependent Repos: 16,712
Dependent Packages: 3,270
Downloads: 10,856,076
Ranking: Top 0.206% by dependent repos Top 0.1136% by downloads Top 0.0251% by dependent pkgs
PR Status
Open 630 (45.6%)
Merged 217 (15.7%)
Closed 326 (23.6%)
PR Types
Removal 25 (1.8%)
Minor 640 (46.3%)
Major 233 (16.9%)
Patch 274 (19.8%)