chore(fastify): Update dependency fastify to v5.12.5 [SECURITY] - #10058
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
@clerk/astro
@clerk/backend
@clerk/chrome-extension
@clerk/clerk-js
@clerk/electron
@clerk/electron-passkeys
@clerk/eslint-plugin
@clerk/expo
@clerk/expo-biometrics
@clerk/expo-google-signin
@clerk/expo-passkeys
@clerk/express
@clerk/fastify
@clerk/hono
@clerk/localizations
@clerk/mosaic
@clerk/nextjs
@clerk/nuxt
@clerk/react
@clerk/react-router
@clerk/shared
@clerk/tanstack-react-start
@clerk/testing
@clerk/ui
@clerk/upgrade
@clerk/vue
commit: |
This PR contains the following updates:
5.8.5→5.12.5Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
CVE-2026-16732 / GHSA-3m5p-2c4r-xxw2
More information
Details
Impact
The fix for CVE-2026-3635 (GHSA-444r-cwp2-x5xf) added a
proxyFn(socket.remoteAddress, 0)guard on theX-Forwarded-*reads inrequest.host,request.protocol,request.hostname,request.ip, andrequest.ips. That guard closes the IP, CIDR, and custom-function forms oftrustProxycorrectly because those forms compile to predicates that inspect the connecting address. The hop-count form (trustProxy: <number>) compiles to a predicate that structurally ignores the address argument, so the guard reduces to0 < tp, always true for anytp >= 1.Applications configured with
trustProxy: <number>(documented as "behind N reverse proxies",trustProxy: 1being the canonical single-proxy setting) remain vulnerable. An attacker who can reach the Fastify origin directly, bypassing the front-facing proxy, can spoof the request fields exactly as in the unpatched version. Impact class matches the parent CVE-2026-3635: host injection in generated URLs, HTTPS-enforcement bypass, secure-cookie / CSRF-origin bypass, host-based routing and cache poisoning.Patches
Patched in fastify 5.12.1. The numeric form of
trustProxyis now disabled at runtime and removed from the TypeScript type union.Workarounds
trustProxyvalue that validates the connecting address. Custom functions must inspect theaddressargument, not only the hop index.Severity
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
CVE-2026-18504 / GHSA-w2qp-rph6-63g4
More information
Details
Impact
fastifybefore 5.12.1, when a route uses a root-level primitive body schema (for example an integer with a minimum and maximum) and the default type coercion, validates the coerced value but exposes the original, uncoerced value to the route handler. For example, a JSON body"10"is coerced to the number10and passes an integer 1 to 10 schema, butrequest.bodystays the string"10". An application that trusts the validated type is handed a value that did not satisfy the schema, which can bypass limits the application enforces on that typed value. Object and array body schemas are not affected, they coerce their members in place.Patches
Upgrade to
fastify5.12.1.Workarounds
Until you can upgrade, avoid relying on the validated type of a root primitive body. Wrap the value in an object schema (object properties are coerced in place), for example accept
{ "value": 10 }and readrequest.body.value, or re-check the type in the handler.Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to header validation bypass via incomplete schema case normalization
CVE-2026-84428 / GHSA-9q9j-q6p8-xq58
More information
Details
Impact
Fastify lowercases header-schema property names before compiling the schema, because Node.js stores request header names in lowercase. That normalization was incomplete: it lowercased only top-level
propertieskeys and the rootrequiredarray, and did not lowercase the JSON Schema Draft 7dependencieskeyword (its trigger keys and dependent property names) or names in nested subschemas. As a result, a header schema that usesdependenciesto require one header when another is present (for exampleX-AdminrequiringX-Admin-Token) never matches the lowercased request headers, so the dependency assertion is silently skipped. An unauthenticated remote client can send the header that activates a privileged path while omitting the header the dependency was meant to require, bypassing a schema-enforced security control. The header schema is idiomatic, valid JSON Schema Draft 7, and no custom validator, malformed request, or misconfiguration is required.Patches
Header-schema names are now normalized across all schema positions (
properties,required,dependencies,dependentRequired,dependentSchemas, and nested subschemas). Patched in fastify5.12.2. The fix is also included in the6.0.0release. Header schemas referenced through an external shared$ref(registered withaddSchema) are not reached by this normalization and now emit anFSTSEC002startup warning; inline the header schema to keep case-insensitive assertions in effect.Workarounds
If upgrading is not immediately possible, write header-schema names in lowercase so the
dependenciesand other case-sensitive assertions match Node's lowercased request headers, or enforce the cross-header requirement in anonRequestorpreValidationhook instead of the schema.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to request validation bypass via skipped boolean false schemas
CVE-2026-84469 / GHSA-hwr6-493r-vm6h
More information
Details
Impact
Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean
falseas a valid schema that rejects every instance, but becausefalseis falsy, a route that setbody,querystring,params, orheaderstofalsehad that part left uncompiled: no validator was attached and the request reached the handler. An application that usedfalseas a deny-all schema to make a route unreachable was therefore fully bypassed, and an unauthenticated remote client could reach the handler with any input. The same applied to the documentedqueryalias forquerystring. This is a complete bypass rather than a weak-schema issue, sincefalseis the strongest JSON Schema assertion and must always fail.Patches
Request-part schemas are now selected by an explicit presence check rather than truthiness, so a boolean
false(ortrue) schema is compiled and enforced, including through thequeryalias. Patched in fastify5.12.2. The fix is also included in the6.0.0release.Workarounds
If upgrading is not immediately possible, express a deny-all request schema with an always-failing object schema instead of the boolean
false(for example{ "not": {} }), or reject the request in anonRequesthook.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
CVE-2026-76169 / GHSA-p68q-wchp-6fh7
More information
Details
Impact
Fastify routes a malformed URL under one plugin prefix to the custom not-found handler of a different sibling plugin, invoking the handler registered last and skipping the
preHandlerdeclared in itssetNotFoundHandler(). When the request method has no route in the main router, a malformed request target reaches Fastify's internal not-found router before URL decoding and is dispatched through a single shared handler pointer, regardless of prefix and without the normal request lifecycle. An unauthenticated request to a public prefix can therefore reach an authentication-protected not-found handler registered under a different prefix and receive its full response, breaking prefix encapsulation and bypassing the authentication hook. Applications whose private or tenant fallbacks return protected data from a not-found handler are affected.Patches
Patched in fastify 5.12.2. Malformed URLs are now routed through the configured
onBadUrlandonMaxParamLengthhandlers so they fail closed before any application not-found handler runs, and the shared not-found handler pointer has been removed.Workarounds
Reject malformed request targets before they reach the application, for example at an upstream proxy or gateway, and do not rely on a not-found handler to serve protected data. A global
onRequestauthentication hook does not mitigate this, because the malformed-URL path skips it.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to request body replacement via an async validation result collision
CVE-2026-84504 / GHSA-667r-xxjv-c9mm
More information
Details
Impact
Fastify runs a route's validator and, for a result shaped like
{ value, error }, unwraps it: anerrorbecomes a validation failure andvaluereplaces the request part. This convention is intended for synchronous custom compilers (for example Joi). A JSON Schema$asyncvalidator, however, resolves with the validated data itself, so Fastify applied the same unwrapping to it. If a request part validated by an$asyncschema contains avalueproperty, Fastify replaced the whole request part with that nested value before the handler ran, so avalueorerrorproperty in the payload was attacker-controlled. An application that dispatches operations from the validated request body could then act on data that never satisfied the route schema, leading to unauthorized state changes or disclosure. Reaching the vulnerable path requires the route to use an$asyncrequest schema.Patches
Fastify no longer treats an asynchronous validation result as a
{ value, error }wrapper: an async validator's resolved value is used only to determine pass or fail, and it can no longer replace the request part or inject an error. The synchronous custom-compiler contract is unchanged. Patched in fastify5.12.2and6.0.0.Workarounds
If upgrading is not immediately possible, avoid
$asyncrequest schemas, or perform the security-sensitive check in anonRequestorpreHandlerhook rather than relying on the schema-validated request part. Custom async validator compilers should signal failure by throwing (rejecting) rather than returning an{ error }object.Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
CVE-2026-92081 / GHSA-4mh8-r7rc-xpvc
More information
Details
Impact
fastifycrashes with an uncaughtERR_HTTP2_INVALID_CONNECTION_HEADERSexception when a route that registers a response trailer viareply.trailer()is served over HTTP/2. Fastify unconditionally adds theTransfer-Encoding: chunkedheader when a trailer is set, which is forbidden on HTTP/2, so Node.js throws while serializing the response headers. The exception is not caught and becomes an uncaughtException, terminating the Node.js process.One unauthenticated HTTP/2 request to any route that uses trailers is enough to crash the server, dropping all in-flight requests, and the request can be repeated to keep the process down. Applications are affected only when HTTP/2 is enabled (
http2: true) and at least one route registers a trailer. HTTP/1.x responses are not affected.Patches
Upgrade to
fastify5.12.5or later.Workarounds
Avoid registering response trailers with
reply.trailer()on routes served over HTTP/2 until upgrading.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
fastify/fastify (fastify)
v5.12.5Compare Source
What's Changed
Full Changelog: fastify/fastify@v5.12.4...v5.12.5
v5.12.4Compare Source
Fixed the
fastify.jsversion mismatch.Full Changelog: fastify/fastify@v5.12.2...v5.12.4
v5.12.3Compare Source
v5.12.2Compare Source
What's Changed
Full Changelog: fastify/fastify@v5.12.1...v5.12.2
v5.12.1Compare Source
What's Changed
Full Changelog: fastify/fastify@v5.12.0...v5.12.1
v5.12.0Compare Source
What's Changed
Reply.prototype.mediaTypeby @github-actions[bot] in #6946undefinedfor invalid media types by @github-actions[bot] in #6947Full Changelog: fastify/fastify@v5.11.3...v5.12.0
v5.11.3Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v5.11.2...v5.11.3
v5.11.2Compare Source
v5.11.1Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v5.11.0...v5.11.1
v5.11.0Compare Source
What's Changed
Content-Typeparameter values by @aquie00t in #6865New Contributors
Full Changelog: fastify/fastify@v5.10.0...v5.11.0
v5.10.0Compare Source
v5.9.0Compare Source
What's Changed
findwithsomeinhasKeyfor correct boolean semantics by @aquie00t in #6759AssertionErrorwithFST_ERR_PLUGIN_DEPENDENCY_NOT_REGISTEREDincheckDependenciesby @aquie00t in #6774New Contributors
Full Changelog: fastify/fastify@v5.8.5...v5.9.0
Configuration
📅 Schedule: (in timezone GMT)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.