CVE-2026-84504: Schema Validation Bypass via Async Validation Result Collision in Fastify
Vulnerability ID: CVE-2026-84504
CVSS Score: 8.1
Published: 2026-09-30
An API contract mismatch in the Fastify web framework allows remote attackers to bypass schema validation when asynchronous schema validators are used. When a route uses async validation, the validator resolves with the raw request body. If the body contains a root-level key named 'value', the validation runner interprets this as a synchronous wrapper envelope, extracting and promoting the unvalidated nested content to the root level of request.body.
TL;DR
An API contract collision in Fastify's validation runner allows attackers to bypass JSON Schema validation by embedding nested, unvalidated payloads inside a root-level 'value' key, which is then promoted to the root request body.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-20
- Attack Vector: Network
- CVSS Score: 8.1 (High)
- Exploit Status: poc
- KEV Status: Not Listed
- Impact: Validation Bypass / Parameter Injection
Affected Systems
- Fastify applications utilizing asynchronous JSON schema validation prior to version 5.12.2
-
fastify: < 5.12.2 (Fixed in:
5.12.2)
Code Analysis
Commit: f02d8d4
Fix: process async validation result correctly and do not unwrap as sync wrapper
Mitigation Strategies
- Upgrade Fastify to version 5.12.2 or newer to patch the validation runner.
- Set 'additionalProperties: false' on asynchronous route schemas to block arbitrary 'value' keys.
- Implement a preValidation hook to sanitize or reject payloads containing root-level 'value' or 'error' properties.
Remediation Steps:
- Identify all routes using asynchronous validation schemas ($async: true).
- Execute 'npm install fastify@latest' or 'yarn upgrade fastify' to update dependencies.
- Verify that dependencies have resolved to version 5.12.2 or higher using 'npm list fastify'.
- Deploy the updated application to staging environments and run regression tests targeting validator endpoints.
References
- NVD Detailed View
- CVE.org Official Record
- GitHub Security Advisory
- OpenJS Foundation Security Portal
Read the full report for CVE-2026-84504 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)