GHSA-4mh8-r7rc-xpvc: Medium severity npm/fastify vulnerability
Impact
fastify crashes with an uncaught ERRHTTP2INVALIDCONNECTIONHEADERS exception when a route that registers a response trailer via reply.trailer() is served over HTTP/2. Fastify unconditionally adds the Transfer-Encoding: chunked header when a trailer is set, which is forbidden on HTTP/2, so Node.js throws while serializing the response headers. The exception is not caught and becomes an uncaughtException, terminating the Node.js process.
One unauthenticated HTTP/2 request to any route that uses trailers is enough to crash the server, dropping all in-flight requests, and the request can be repeated to keep the process down. Applications are affected only when HTTP/2 is enabled (http2: true) and at least one route registers a trailer. HTTP/1.x responses are not affected.
Patches
Upgrade to fastify 5.12.5 or later.
Workarounds
Avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until upgrading.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/fastifyto a version that resolves this vulnerability.Fixed in 5.12.5 - Upgrade
Upgrade
fastifyto a version that resolves this vulnerability.Fixed in 5.12.5 - Configuration
Avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until upgrading.
Fastify response trailers via reply.trailer() = disabled
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service issue?
Only applications with Fastify HTTP/2 enabled using `http2: true` and at least one route that registers a response trailer with `reply.trailer()` are affected. HTTP/1.x responses are not affected.
What does an attacker need to do to trigger the crash?
An unauthenticated attacker needs only to send an HTTP/2 request to a route that uses response trailers. A single request can terminate the Node.js process, and repeated requests can keep it unavailable.
What can be done if an upgrade cannot be applied immediately?
Avoid registering response trailers with `reply.trailer()` on routes served over HTTP/2 until Fastify can be upgraded. The documented fixed version is Fastify 5.12.5 or later.