CVE-2026-15144: @fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation

Published Jul 29, 2026
·
Updated

@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can control a large address range (a /64 holds 2^64 distinct addresses) and the same address has multiple valid textual representations, an IPv6 capable client can defeat the rate-limit boundary by rotating addresses or by rewriting the same address in different forms. Applications that use @fastify/rate-limit to protect endpoints such as authentication, password reset, OTP delivery, or expensive API calls can be bypassed by IPv6 clients behind a proxy that surfaces IPv6 to the origin when trustProxy is enabled. The issue is fixed in @fastify/rate-limit 11.2.0, where the default key generator normalizes IPv6 addresses to their canonical form, collapses IPv4 mapped IPv6 to IPv4, and applies a configurable prefix mask (default /64) via a new ipv6Subnet option.

Affected Software

2 affected components
npm/@fastify/rate-limit<11.2.0
fastify Fastify\/rate-limit Node.js<11.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @fastify/rate-limit to a version that resolves this vulnerability.

    Fixed in 11.2.0

Event History

Jul 29, 2026
CVE Published
via MITRE·04:10 PM
Data Sourced
via MITRE·04:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-15144?

The severity of CVE-2026-15144 is high with a CVSS score of 7.3.

2

What is the risk associated with CVE-2026-15144?

CVE-2026-15144 has a risk rating of 51, indicating a significant risk level.

3

How do I fix CVE-2026-15144?

Upgrade @fastify/rate-limit to version 11.2.0 or higher to mitigate the vulnerability in CVE-2026-15144.

4

What does CVE-2026-15144 affect?

CVE-2026-15144 affects the @fastify/rate-limit package prior to version 11.2.0.

5

What type of attack does CVE-2026-15144 allow?

CVE-2026-15144 allows rate-limit bypass via IPv6 address rotation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203