GHSA-9q9j-q6p8-xq58: High severity npm/fastify vulnerability
Impact
Fastify lowercases header-schema property names before compiling the schema, because Node.js stores request header names in lowercase. That normalization was incomplete: it lowercased only top-level properties keys and the root required array, and did not lowercase the JSON Schema Draft 7 dependencies keyword (its trigger keys and dependent property names) or names in nested subschemas. As a result, a header schema that uses dependencies to require one header when another is present (for example X-Admin requiring X-Admin-Token) never matches the lowercased request headers, so the dependency assertion is silently skipped. An unauthenticated remote client can send the header that activates a privileged path while omitting the header the dependency was meant to require, bypassing a schema-enforced security control. The header schema is idiomatic, valid JSON Schema Draft 7, and no custom validator, malformed request, or misconfiguration is required.
Patches
Header-schema names are now normalized across all schema positions (properties, required, dependencies, dependentRequired, dependentSchemas, and nested subschemas). Patched in fastify 5.12.2. The fix is also included in the 6.0.0 release. Header schemas referenced through an external shared $ref (registered with addSchema) are not reached by this normalization and now emit an FSTSEC002 startup warning; inline the header schema to keep case-insensitive assertions in effect.
Workarounds
If upgrading is not immediately possible, write header-schema names in lowercase so the dependencies and other case-sensitive assertions match Node's lowercased request headers, or enforce the cross-header requirement in an onRequest or preValidation hook instead of the schema.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/fastifyto a version that resolves this vulnerability.Fixed in 5.12.2 - Upgrade
Upgrade
fastifyto a version that resolves this vulnerability.Fixed in 5.12.2 - Configuration
Write header-schema names in lowercase so dependencies and other case-sensitive assertions match Node.js lowercased request headers.
Fastify header schema Header-schema property and dependency names = lowercase - Configuration
Inline header schemas instead of referencing them through an external shared $ref registered with addSchema, so normalization applies and FSTSEC002 is avoided.
Fastify header schema External shared $ref = inline schema - Compensating control
Enforce cross-header requirements in an onRequest or preValidation hook instead of relying on the schema.
Event History
Frequently Asked Questions
Which applications are exposed to this bypass?
Applications are exposed when they use Fastify header schemas to enforce a dependency between headers, such as requiring an administrative token when an administrative header is present. The vulnerable behavior applies when the relevant names occur in dependencies or in nested subschemas and are not normalized to match Node.js lowercased request headers.
What does an attacker need to exploit this issue?
An unauthenticated remote client only needs to send the header that activates the protected or privileged path while omitting the header that the schema dependency was intended to require. No custom validator, malformed request, or special misconfiguration is required.
What should be done if the application cannot be patched immediately?
Review header schemas that use dependencies to enforce security-sensitive header combinations, particularly schemas using mixed-case header names or nested subschemas. Do not rely solely on those schema dependencies to require authentication or authorization headers until the application can be updated.
How can teams identify potentially affected schemas?
Inspect Fastify header schemas for dependencies, dependentRequired, dependentSchemas, and nested subschemas containing header names. Schemas that use dependencies to gate privileged behavior should be treated as potentially affected if their header-name handling relies on Fastify normalization.
What version contains the fix?
The issue is patched in Fastify 5.12.2. The fix normalizes header-schema names across properties, required, dependencies, dependentRequired, dependentSchemas, and nested subschemas.