Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Csrf Protection MEDIUM 6.5
CVE-2023-27495

@fastify/csrf-protection is a plugin which helps protect Fastify servers against CSRF attacks. The CSRF protection enforced by the @fastify/csrf-prot…

Fix: 4.1.0 / 6.3.0+
Fix from $1,600 2023-04-20
Fastify Multipart HIGH 7.5
CVE-2023-25576

@fastify/multipart is a Fastify plugin to parse the multipart content-type. Prior to versions 7.4.1 and 6.0.1, @fastify/multipart may experience deni…

Fix: 6.0.1 / 7.4.1+
Fix from $1,950 2023-02-14
Fastify HIGH 8.8
CVE-2022-41919

Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight…

Fix: 3.29.4 / 4.10.2+
Fix from $1,950 2022-11-22
Websocket HIGH 7.5
CVE-2022-39386

@fastify/websocket provides WebSocket support for Fastify. Any application using @fastify/websocket could crash if a specific, malformed packet is se…

Fix: 7.1.1+
Fix from $1,950 2022-11-08
Fastify HIGH 7.5
CVE-2022-39288EPSS 59%

fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of service via malicious use of t…

Fix: 4.8.1+
Fix from $1,950 2022-10-10
Bearer Auth HIGH 7.5
CVE-2022-31142

@fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions 7.0.2 and 8.0.1 does not sec…

Fix: 7.0.2+
Fix from $1,950 2022-07-14
Github Action Merge Dependabot MEDIUM 6.5
CVE-2022-29220

github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-act…

Fix: 3.2.0+
Fix from $1,600 2022-05-31
Fastify Multipart HIGH 7.5
CVE-2021-23597

This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible to crash the application. **No…

Fix: 5.3.1+
Fix from $1,950 2022-02-11
Fastify Static HIGH 8.8
CVE-2021-22964

A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arb…

Fix: 4.4.1+
Fix from $1,950 2021-10-14
Fastify Static MEDIUM 6.1
CVE-2021-22963

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double sl…

Fix: 4.2.4+
Fix from $1,600 2021-10-14
Fastify Csrf MEDIUM 6.5
CVE-2021-29624

fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fastify-csrf prior to 3.1.0 hav…

Fix: 3.1.0+
Fix from $1,600 2021-05-19
Fastify Csrf HIGH 8.8
CVE-2020-28482

This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts…

Fix: 3.0.0+
Fix from $1,950 2021-01-19
Fastify MEDIUM 6.5
CVE-2020-8192

A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the all…

No fix yet
Fix from $1,600 2020-07-30
Fastify Multipart HIGH 7.5
CVE-2020-8136

Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests by sending…

Fix: 1.0.5+
Fix from $1,950 2020-03-20
Fastify HIGH 7.5
CVE-2018-3711

Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very l…

Fix: 0.38.0+
Fix from $1,950 2018-06-07