DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-84504: CVE-2026-84504: Schema Validation Bypass via Async Validation Result Collision in Fastify

CVE-2026-84504: Schema Validation Bypass via Async Validation Result Collision in Fastify

Vulnerability ID: CVE-2026-84504
CVSS Score: 8.1
Published: 2026-09-30

An API contract mismatch in the Fastify web framework allows remote attackers to bypass schema validation when asynchronous schema validators are used. When a route uses async validation, the validator resolves with the raw request body. If the body contains a root-level key named 'value', the validation runner interprets this as a synchronous wrapper envelope, extracting and promoting the unvalidated nested content to the root level of request.body.

TL;DR

An API contract collision in Fastify's validation runner allows attackers to bypass JSON Schema validation by embedding nested, unvalidated payloads inside a root-level 'value' key, which is then promoted to the root request body.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-20
  • Attack Vector: Network
  • CVSS Score: 8.1 (High)
  • Exploit Status: poc
  • KEV Status: Not Listed
  • Impact: Validation Bypass / Parameter Injection

Affected Systems

  • Fastify applications utilizing asynchronous JSON schema validation prior to version 5.12.2
  • fastify: < 5.12.2 (Fixed in: 5.12.2)

Code Analysis

Commit: f02d8d4

Fix: process async validation result correctly and do not unwrap as sync wrapper

Mitigation Strategies

  • Upgrade Fastify to version 5.12.2 or newer to patch the validation runner.
  • Set 'additionalProperties: false' on asynchronous route schemas to block arbitrary 'value' keys.
  • Implement a preValidation hook to sanitize or reject payloads containing root-level 'value' or 'error' properties.

Remediation Steps:

  1. Identify all routes using asynchronous validation schemas ($async: true).
  2. Execute 'npm install fastify@latest' or 'yarn upgrade fastify' to update dependencies.
  3. Verify that dependencies have resolved to version 5.12.2 or higher using 'npm list fastify'.
  4. Deploy the updated application to staging environments and run regression tests targeting validator endpoints.

References


Read the full report for CVE-2026-84504 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)