CVE-2026-92081: Denial of Service via Uncaught Exception on HTTP/2 Response Trailers in Fastify
Vulnerability ID: CVE-2026-92081
CVSS Score: 5.9
Published: 2026-09-30
A protocol validation vulnerability exists in Fastify before version 5.12.5. When serving requests over HTTP/2, Fastify unconditionally injects the forbidden Transfer-Encoding header when response trailers are used, triggering an uncaught exception in Node.js and crashing the process.
TL;DR
Unauthenticated remote HTTP/2 requests to Fastify endpoints utilizing response trailers trigger an uncaught validation exception in Node.js, immediately crashing the server.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-248
- Attack Vector: Network
- CVSS Score: 5.9
- Exploit Status: poc
- KEV Status: Not Listed
- Impact: Denial of Service (DoS)
Affected Systems
- Fastify
-
Fastify: < 5.12.5 (Fixed in:
5.12.5)
Code Analysis
Commit: ad06a4c
fix: prevent adding Transfer-Encoding header on HTTP/2 replies
Exploit Details
- GitHub Security Advisory: Reproduction script and advisory details outlining vulnerability flow.
Mitigation Strategies
- Upgrade Fastify to version 5.12.5 or later.
- Disable HTTP/2 support in Fastify configuration if not strictly necessary.
- Implement conditional trailer registration by verifying the active protocol version before calling reply.trailer().
Remediation Steps:
- Navigate to the application root directory.
- Update the Fastify dependency in package.json to "^5.12.5" or run "npm install fastify@5.12.5".
- Verify that the package-lock.json or yarn.lock file reflects the correct version upgrade.
- Deploy the updated application to staging environment and execute verification tests over HTTP/2 connections.
- Monitor application logs for uncaughtException events during traffic serialization.
References
- GHSA-4mh8-r7rc-xpvc
- Fastify Patch Commit ad06a4c
- Fastify Release v5.12.5
- NVD CVE-2026-92081
- CVE.org CVE-2026-92081
Read the full report for CVE-2026-92081 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)