GHSA-qxhc-wx3p-2wmg

Suggest an improvement
Source
https://github.com/advisories/GHSA-qxhc-wx3p-2wmg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qxhc-wx3p-2wmg/GHSA-qxhc-wx3p-2wmg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qxhc-wx3p-2wmg
Aliases
Published
2026-05-08T17:13:38Z
Modified
2026-05-08T17:41:26Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
@fastify/accepts-serializer Vulnerable to Denial of Service via Unbounded Accept Header Cache Growth
Details

Impact

@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthenticated client could send many distinct but matching Accept header variants to make the cache grow unbounded. Under sustained load, this can exhaust the Node.js heap and crash the process.

Patches

Update to @fastify/accepts-serializer >= 6.0.4. The cache is now bounded by an LRU with a default size of 100 entries, configurable via the new cacheSize plugin option.

Workarounds

None. Upgrade is required.

Database specific
{
    "cwe_ids":  [
        "CWE-770"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-08T17:13:38Z",
    "nvd_published_at":  "2026-05-04T20:16:21Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @fastify/accepts-serializer

Package

Name
@fastify/accepts-serializer
View open source insights on deps.dev
Purl
pkg:npm/%40fastify/accepts-serializer

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.4

Database specific

last_known_affected_version_range
"<= 6.0.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qxhc-wx3p-2wmg/GHSA-qxhc-wx3p-2wmg.json"