GHSA-9q9j-q6p8-xq58: High severity npm/fastify vulnerability

Published Sep 30, 2026
·
Updated

Impact

Fastify lowercases header-schema property names before compiling the schema, because Node.js stores request header names in lowercase. That normalization was incomplete: it lowercased only top-level properties keys and the root required array, and did not lowercase the JSON Schema Draft 7 dependencies keyword (its trigger keys and dependent property names) or names in nested subschemas. As a result, a header schema that uses dependencies to require one header when another is present (for example X-Admin requiring X-Admin-Token) never matches the lowercased request headers, so the dependency assertion is silently skipped. An unauthenticated remote client can send the header that activates a privileged path while omitting the header the dependency was meant to require, bypassing a schema-enforced security control. The header schema is idiomatic, valid JSON Schema Draft 7, and no custom validator, malformed request, or misconfiguration is required.

Patches

Header-schema names are now normalized across all schema positions (properties, required, dependencies, dependentRequired, dependentSchemas, and nested subschemas). Patched in fastify 5.12.2. The fix is also included in the 6.0.0 release. Header schemas referenced through an external shared $ref (registered with addSchema) are not reached by this normalization and now emit an FSTSEC002 startup warning; inline the header schema to keep case-insensitive assertions in effect.

Workarounds

If upgrading is not immediately possible, write header-schema names in lowercase so the dependencies and other case-sensitive assertions match Node's lowercased request headers, or enforce the cross-header requirement in an onRequest or preValidation hook instead of the schema.

Affected Software

1 affected componentFixes available
npm/fastify<5.12.2
5.12.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/fastify to a version that resolves this vulnerability.

    Fixed in 5.12.2
  2. Upgrade

    Upgrade fastify to a version that resolves this vulnerability.

    Fixed in 5.12.2
  3. Configuration

    Write header-schema names in lowercase so dependencies and other case-sensitive assertions match Node.js lowercased request headers.

    Fastify header schema Header-schema property and dependency names = lowercase
  4. Configuration

    Inline header schemas instead of referencing them through an external shared $ref registered with addSchema, so normalization applies and FSTSEC002 is avoided.

    Fastify header schema External shared $ref = inline schema
  5. Compensating control

    Enforce cross-header requirements in an onRequest or preValidation hook instead of relying on the schema.

Event History

Sep 30, 2026
Advisory Published
via GitHub·11:44 PM
Data Sourced
via GitHub·11:44 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed to this bypass?

Applications are exposed when they use Fastify header schemas to enforce a dependency between headers, such as requiring an administrative token when an administrative header is present. The vulnerable behavior applies when the relevant names occur in dependencies or in nested subschemas and are not normalized to match Node.js lowercased request headers.

2

What does an attacker need to exploit this issue?

An unauthenticated remote client only needs to send the header that activates the protected or privileged path while omitting the header that the schema dependency was intended to require. No custom validator, malformed request, or special misconfiguration is required.

3

What should be done if the application cannot be patched immediately?

Review header schemas that use dependencies to enforce security-sensitive header combinations, particularly schemas using mixed-case header names or nested subschemas. Do not rely solely on those schema dependencies to require authentication or authorization headers until the application can be updated.

4

How can teams identify potentially affected schemas?

Inspect Fastify header schemas for dependencies, dependentRequired, dependentSchemas, and nested subschemas containing header names. Schemas that use dependencies to gate privileged behavior should be treated as potentially affected if their header-name handling relies on Fastify normalization.

5

What version contains the fix?

The issue is patched in Fastify 5.12.2. The fix normalizes header-schema names across properties, required, dependencies, dependentRequired, dependentSchemas, and nested subschemas.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203