DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-84469: CVE-2026-84469: Request Validation Bypass in Fastify via Loose Boolean Schema Evaluation

CVE-2026-84469: Request Validation Bypass in Fastify via Loose Boolean Schema Evaluation

Vulnerability ID: CVE-2026-84469
CVSS Score: 7.5
Published: 2026-09-30

CVE-2026-84469 is a high-severity request validation bypass vulnerability in the Fastify Node.js web framework. In versions prior to 5.12.2, Fastify uses loose truthiness checks to decide whether to compile request schemas. When a component (such as the body) is explicitly configured with a boolean 'false' schema—which under JSON Schema Draft 7 acts as a 'deny-all' constraint—Fastify's internal logic evaluates this as a falsy value and skips compilation entirely. This allows unauthenticated remote attackers to send arbitrary payloads to these endpoints, bypassing validation checks and directly executing backend route handlers.

TL;DR

Fastify fails to compile validation schemas configured as boolean 'false', causing 'deny-all' schemas to be completely ignored. Unauthenticated remote attackers can bypass payload validation and execute backend route handlers.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-20: Improper Input Validation
  • Attack Vector: Network (Remote)
  • CVSS Score: 7.5 (High)
  • EPSS Score: 0.00492 (Percentile: 39.86%)
  • Impact: Validation Bypass / Integrity Compromise
  • Exploit Status: PoC Available
  • KEV Status: Not Listed

Affected Systems

  • Fastify Web Framework
  • Fastify: >= 0.1.0, < 5.12.2 (Fixed in: 5.12.2)

Code Analysis

Commit: 7de6e81

fix(validation): compile boolean false request schemas

Mitigation Strategies

  • Upgrade to Fastify version 5.12.2 or later.
  • Rewrite boolean false schemas to equivalent explicit JSON objects that reject all input.
  • Implement preValidation or preHandler hooks to manually drop requests on affected endpoints.

Remediation Steps:

  1. Analyze the codebase to locate routes where body: false, querystring: false, params: false, or headers: false are declared.
  2. Apply the patch by updating the Fastify package dependency using 'npm install fastify@5.12.2' or 'yarn upgrade fastify@5.12.2'.
  3. Verify that endpoints configured with boolean false schemas properly return HTTP 400 Bad Request responses when subjected to random testing payloads.

References


Read the full report for CVE-2026-84469 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)