CVE-2026-84469: Request Validation Bypass in Fastify via Loose Boolean Schema Evaluation
Vulnerability ID: CVE-2026-84469
CVSS Score: 7.5
Published: 2026-09-30
CVE-2026-84469 is a high-severity request validation bypass vulnerability in the Fastify Node.js web framework. In versions prior to 5.12.2, Fastify uses loose truthiness checks to decide whether to compile request schemas. When a component (such as the body) is explicitly configured with a boolean 'false' schema—which under JSON Schema Draft 7 acts as a 'deny-all' constraint—Fastify's internal logic evaluates this as a falsy value and skips compilation entirely. This allows unauthenticated remote attackers to send arbitrary payloads to these endpoints, bypassing validation checks and directly executing backend route handlers.
TL;DR
Fastify fails to compile validation schemas configured as boolean 'false', causing 'deny-all' schemas to be completely ignored. Unauthenticated remote attackers can bypass payload validation and execute backend route handlers.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-20: Improper Input Validation
- Attack Vector: Network (Remote)
- CVSS Score: 7.5 (High)
- EPSS Score: 0.00492 (Percentile: 39.86%)
- Impact: Validation Bypass / Integrity Compromise
- Exploit Status: PoC Available
- KEV Status: Not Listed
Affected Systems
- Fastify Web Framework
-
Fastify: >= 0.1.0, < 5.12.2 (Fixed in:
5.12.2)
Code Analysis
Commit: 7de6e81
fix(validation): compile boolean false request schemas
Mitigation Strategies
- Upgrade to Fastify version 5.12.2 or later.
- Rewrite boolean false schemas to equivalent explicit JSON objects that reject all input.
- Implement preValidation or preHandler hooks to manually drop requests on affected endpoints.
Remediation Steps:
- Analyze the codebase to locate routes where body: false, querystring: false, params: false, or headers: false are declared.
- Apply the patch by updating the Fastify package dependency using 'npm install fastify@5.12.2' or 'yarn upgrade fastify@5.12.2'.
- Verify that endpoints configured with boolean false schemas properly return HTTP 400 Bad Request responses when subjected to random testing payloads.
References
Read the full report for CVE-2026-84469 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)