Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2023-27495 @fastify/csrf-protection is a plugin which helps protect Fastify servers against CSRF attacks. The CSRF protection enforced by the @fastify/csrf-prot… Csrf Protection 4.1.0 / 6.3.0+ Fix from $1,6002023-04-20 HIGH 7.5 CVE-2023-25576 @fastify/multipart is a Fastify plugin to parse the multipart content-type. Prior to versions 7.4.1 and 6.0.1, @fastify/multipart may experience deni… Fastify Multipart 6.0.1 / 7.4.1+ Fix from $1,9502023-02-14 HIGH 8.8 CVE-2022-41919 Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight… Fastify 3.29.4 / 4.10.2+ Fix from $1,9502022-11-22 HIGH 7.5 CVE-2022-39386 @fastify/websocket provides WebSocket support for Fastify. Any application using @fastify/websocket could crash if a specific, malformed packet is se… Websocket 7.1.1+ Fix from $1,9502022-11-08 HIGH 7.5 CVE-2022-39288EPSS 59% fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of service via malicious use of t… Fastify 4.8.1+ Fix from $1,9502022-10-10 HIGH 7.5 CVE-2022-31142 @fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions 7.0.2 and 8.0.1 does not sec… Bearer Auth 7.0.2+ Fix from $1,9502022-07-14 MEDIUM 6.5 CVE-2022-29220 github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-act… Github Action Merge Dependabot 3.2.0+ Fix from $1,6002022-05-31 HIGH 7.5 CVE-2021-23597 This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible to crash the application. **No… Fastify Multipart 5.3.1+ Fix from $1,9502022-02-11 HIGH 8.8 CVE-2021-22964 A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arb… Fastify Static 4.4.1+ Fix from $1,9502021-10-14 MEDIUM 6.1 CVE-2021-22963 A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double sl… Fastify Static 4.2.4+ Fix from $1,6002021-10-14 MEDIUM 6.5 CVE-2021-29624 fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fastify-csrf prior to 3.1.0 hav… Fastify Csrf 3.1.0+ Fix from $1,6002021-05-19 HIGH 8.8 CVE-2020-28482 This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts… Fastify Csrf 3.0.0+ Fix from $1,9502021-01-19 MEDIUM 6.5 CVE-2020-8192 A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the all… Fastify No fix yet Fix from $1,6002020-07-30 HIGH 7.5 CVE-2020-8136 Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests by sending… Fastify Multipart 1.0.5+ Fix from $1,9502020-03-20 HIGH 7.5 CVE-2018-3711 Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very l… Fastify 0.38.0+ Fix from $1,9502018-06-07