CVE-2022-31142: Potential Timing Attack Vector in @fastify/bearer-auth

Published Jul 14, 2022
·
Updated

@fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions 7.0.2 and 8.0.1 does not securely use crypto.timingSafeEqual. A malicious attacker could estimate the length of one valid bearer token. According to the corresponding RFC 6750, the bearer token has only base64 valid characters, reducing the range of characters for a brute force attack. Version 7.0.2 and 8.0.1 of @fastify/bearer-auth contain a patch. There are currently no known workarounds. The package fastify-bearer-auth, which covers versions 6.0.3 and prior, is also vulnerable starting at version 5.0.1. Users of fastify-bearer-auth should upgrade to a patched version of @fastify/bearer-auth.

Affected Software

2 affected components
fastify Bearer-auth Node.js>=5.0.1<7.0.2
fastify Bearer-auth Node.js=8.0.0

Event History

Jul 14, 2022
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2022-31142?

The severity of CVE-2022-31142 is high.

2

How does CVE-2022-31142 affect Fastify Bearer-auth?

CVE-2022-31142 affects Fastify Bearer-auth versions 5.0.1 to 7.0.2 and version 8.0.0.

3

What is the vulnerability of CVE-2022-31142?

CVE-2022-31142 is a vulnerability in @fastify/bearer-auth that does not securely use crypto.timingSafeEqual, allowing a malicious attacker to estimate the length of a valid bearer token.

4

How can I fix CVE-2022-31142?

To fix CVE-2022-31142, update Fastify Bearer-auth to version 7.0.2 or higher for versions 5.0.1 to 7.0.2, and update to version 8.0.1 or higher for version 8.0.0.

5

Where can I find more information about CVE-2022-31142?

You can find more information about CVE-2022-31142 at the following references: [GitHub commit 0c468a616d7e56126dc468150f6a5a92e530b8e4](https://github.com/fastify/fastify-bearer-auth/commit/0c468a616d7e56126dc468150f6a5a92e530b8e4), [GitHub commit 39353b15409ee99474545f615ffb16180cf3b716](https://github.com/fastify/fastify-bearer-auth/commit/39353b15409ee99474545f615ffb16180cf3b716), [GitHub commit f921a0582dc83112039004a9b5041141b50c5b3f](https://github.com/fastify/fastify-bearer-auth/commit/f921a0582dc83112039004a9b5041141b50c5b3f).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203