DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-92081: CVE-2026-92081: Denial of Service via Uncaught Exception on HTTP/2 Response Trailers in Fastify

CVE-2026-92081: Denial of Service via Uncaught Exception on HTTP/2 Response Trailers in Fastify

Vulnerability ID: CVE-2026-92081
CVSS Score: 5.9
Published: 2026-09-30

A protocol validation vulnerability exists in Fastify before version 5.12.5. When serving requests over HTTP/2, Fastify unconditionally injects the forbidden Transfer-Encoding header when response trailers are used, triggering an uncaught exception in Node.js and crashing the process.

TL;DR

Unauthenticated remote HTTP/2 requests to Fastify endpoints utilizing response trailers trigger an uncaught validation exception in Node.js, immediately crashing the server.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-248
  • Attack Vector: Network
  • CVSS Score: 5.9
  • Exploit Status: poc
  • KEV Status: Not Listed
  • Impact: Denial of Service (DoS)

Affected Systems

  • Fastify
  • Fastify: < 5.12.5 (Fixed in: 5.12.5)

Code Analysis

Commit: ad06a4c

fix: prevent adding Transfer-Encoding header on HTTP/2 replies

Exploit Details

Mitigation Strategies

  • Upgrade Fastify to version 5.12.5 or later.
  • Disable HTTP/2 support in Fastify configuration if not strictly necessary.
  • Implement conditional trailer registration by verifying the active protocol version before calling reply.trailer().

Remediation Steps:

  1. Navigate to the application root directory.
  2. Update the Fastify dependency in package.json to "^5.12.5" or run "npm install fastify@5.12.5".
  3. Verify that the package-lock.json or yarn.lock file reflects the correct version upgrade.
  4. Deploy the updated application to staging environment and execute verification tests over HTTP/2 connections.
  5. Monitor application logs for uncaughtException events during traffic serialization.

References


Read the full report for CVE-2026-92081 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)