DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-84428: CVE-2026-84428: Schema Validation Bypass in Fastify Header Normalization

CVE-2026-84428: Schema Validation Bypass in Fastify Header Normalization

Vulnerability ID: CVE-2026-84428
CVSS Score: 7.5
Published: 2026-09-30

A validation bypass vulnerability exists in Fastify web framework prior to version 5.12.2. The flaw stems from shallow normalization of header validation schemas, which fails to lowercase nested or conditional schema rules (like JSON Schema dependencies or dependentRequired) defined in mixed or canonical casing. Consequently, because Node.js normalizes incoming HTTP request headers to lowercase, the compiled validator fails to match these headers against the un-normalized mixed-case schema triggers, silently skipping conditional checks and allowing unauthenticated attackers to bypass authorization or security headers.

TL;DR

A shallow header-schema normalization bug in Fastify < 5.12.2 allows unauthenticated remote attackers to bypass critical conditional header validation rules, silently skipping security checks if trigger headers are defined in mixed-case.


⚠️ Exploit Status: POC

Technical Details

  • Vulnerability Type: Improper Handling of Case Sensitivity (CWE-178)
  • Attack Vector: Network (AV:N)
  • CVSS Base Score: 7.5 (High)
  • EPSS Score: 0.00524 (Percentile: 42.21%)
  • Exploit Maturity: Proof-of-Concept (PoC)
  • CISA KEV Status: Not Listed

Affected Systems

  • Fastify < 5.12.2
  • Fastify: < 5.12.2 (Fixed in: 5.12.2)

Code Analysis

Commit: 179619c

Fix: recursive lowercase headers schema and detect external ref to trigger FSTSEC002 warning

Commit: 942a2be

Release v5.12.2 containing fix for header schema validation bypass

Exploit Details

  • GitHub Test Suite: Programmatic proof-of-concept showing dependency verification bypass using mixed-case header configurations.

Mitigation Strategies

  • Upgrade Fastify to version 5.12.2 or higher to enable deep recursive schema normalization.
  • Inline all header validation schemas instead of using external definitions referenced via $ref.
  • Manually normalize all validation schemas to lowercase for both properties and conditional triggers.
  • Implement programmatic preHandler hooks as a defense-in-depth security layer to manually verify critical headers.

Remediation Steps:

  1. Execute npm install fastify@latest or yarn upgrade fastify to pull Fastify v5.12.2+.
  2. Search your application log output for the Fastify Security Warning code FSTSEC002.
  3. Identify any schemas causing this warning and refactor them to inline their schemas instead of using external $ref statements.
  4. Review header schema configurations and convert mixed-case property and dependency declarations to lowercase for consistency.

References


Read the full report for CVE-2026-84428 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)