GHSA-hwr6-493r-vm6h

Suggest an improvement
Source
https://github.com/advisories/GHSA-hwr6-493r-vm6h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hwr6-493r-vm6h/GHSA-hwr6-493r-vm6h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hwr6-493r-vm6h
Aliases
Published
2026-09-30T23:44:58Z
Modified
2026-10-01T00:00:04Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
fastify vulnerable to request validation bypass via skipped boolean false schemas
Details

Impact

Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance, but because false is falsy, a route that set body, querystring, params, or headers to false had that part left uncompiled: no validator was attached and the request reached the handler. An application that used false as a deny-all schema to make a route unreachable was therefore fully bypassed, and an unauthenticated remote client could reach the handler with any input. The same applied to the documented query alias for querystring. This is a complete bypass rather than a weak-schema issue, since false is the strongest JSON Schema assertion and must always fail.

Patches

Request-part schemas are now selected by an explicit presence check rather than truthiness, so a boolean false (or true) schema is compiled and enforced, including through the query alias. Patched in fastify 5.12.2. The fix is also included in the 6.0.0 release.

Workarounds

If upgrading is not immediately possible, express a deny-all request schema with an always-failing object schema instead of the boolean false (for example { "not": {} }), or reject the request in an onRequest hook.

Database specific
{
    "cwe_ids":  [
        "CWE-20"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-30T23:44:58Z",
    "nvd_published_at":  "2026-09-04T10:17:13Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / fastify

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.12.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hwr6-493r-vm6h/GHSA-hwr6-493r-vm6h.json"