CVE-2026-84428: Schema Validation Bypass in Fastify Header Normalization
Vulnerability ID: CVE-2026-84428
CVSS Score: 7.5
Published: 2026-09-30
A validation bypass vulnerability exists in Fastify web framework prior to version 5.12.2. The flaw stems from shallow normalization of header validation schemas, which fails to lowercase nested or conditional schema rules (like JSON Schema dependencies or dependentRequired) defined in mixed or canonical casing. Consequently, because Node.js normalizes incoming HTTP request headers to lowercase, the compiled validator fails to match these headers against the un-normalized mixed-case schema triggers, silently skipping conditional checks and allowing unauthenticated attackers to bypass authorization or security headers.
TL;DR
A shallow header-schema normalization bug in Fastify < 5.12.2 allows unauthenticated remote attackers to bypass critical conditional header validation rules, silently skipping security checks if trigger headers are defined in mixed-case.
⚠️ Exploit Status: POC
Technical Details
- Vulnerability Type: Improper Handling of Case Sensitivity (CWE-178)
- Attack Vector: Network (AV:N)
- CVSS Base Score: 7.5 (High)
- EPSS Score: 0.00524 (Percentile: 42.21%)
- Exploit Maturity: Proof-of-Concept (PoC)
- CISA KEV Status: Not Listed
Affected Systems
- Fastify < 5.12.2
-
Fastify: < 5.12.2 (Fixed in:
5.12.2)
Code Analysis
Commit: 179619c
Fix: recursive lowercase headers schema and detect external ref to trigger FSTSEC002 warning
Commit: 942a2be
Release v5.12.2 containing fix for header schema validation bypass
Exploit Details
- GitHub Test Suite: Programmatic proof-of-concept showing dependency verification bypass using mixed-case header configurations.
Mitigation Strategies
- Upgrade Fastify to version 5.12.2 or higher to enable deep recursive schema normalization.
- Inline all header validation schemas instead of using external definitions referenced via $ref.
- Manually normalize all validation schemas to lowercase for both properties and conditional triggers.
- Implement programmatic preHandler hooks as a defense-in-depth security layer to manually verify critical headers.
Remediation Steps:
- Execute
npm install fastify@latestoryarn upgrade fastifyto pull Fastify v5.12.2+. - Search your application log output for the Fastify Security Warning code
FSTSEC002. - Identify any schemas causing this warning and refactor them to inline their schemas instead of using external
$refstatements. - Review header schema configurations and convert mixed-case property and dependency declarations to lowercase for consistency.
References
- GHSA-9q9j-q6p8-xq58: Case insensitivity bypass in header validation schemas
- NVD - CVE-2026-84428
- OpenJS Foundation Security Advisories
Read the full report for CVE-2026-84428 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)