GHSA-hwr6-493r-vm6h: Input Validation

Published Sep 30, 2026
·
Updated

Impact

Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance, but because false is falsy, a route that set body, querystring, params, or headers to false had that part left uncompiled: no validator was attached and the request reached the handler. An application that used false as a deny-all schema to make a route unreachable was therefore fully bypassed, and an unauthenticated remote client could reach the handler with any input. The same applied to the documented query alias for querystring. This is a complete bypass rather than a weak-schema issue, since false is the strongest JSON Schema assertion and must always fail.

Patches

Request-part schemas are now selected by an explicit presence check rather than truthiness, so a boolean false (or true) schema is compiled and enforced, including through the query alias. Patched in fastify 5.12.2. The fix is also included in the 6.0.0 release.

Workarounds

If upgrading is not immediately possible, express a deny-all request schema with an always-failing object schema instead of the boolean false (for example { "not": {} }), or reject the request in an onRequest hook.

Affected Software

1 affected componentFixes available
npm/fastify<5.12.2
5.12.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/fastify to a version that resolves this vulnerability.

    Fixed in 5.12.2
  2. Upgrade

    Upgrade fastify to a version that resolves this vulnerability.

    Fixed in 5.12.2
  3. Configuration

    Replace a boolean false deny-all schema with an always-failing object schema such as { "not": {} } so the request part is rejected.

    Fastify request-part schema body/querystring/query/params/headers schema = {"not":{}}

Event History

Sep 30, 2026
Advisory Published
via GitHub·11:44 PM
Data Sourced
via GitHub·11:44 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are realistically exposed?

Applications are exposed if they use a boolean false schema for a route's body, querystring, query alias, params, or headers to reject all requests. In affected Fastify versions, that request part receives no compiled validator and the handler remains reachable.

2

What does an attacker need to exploit this behavior?

An unauthenticated remote client can exploit it without special input, provided the target route relies on a false request-part schema as a deny-all control. The client can reach the handler with any input.

3

How can I identify potentially affected routes?

Review route schemas for body, querystring, query, params, or headers set to the boolean value false, especially where this was intended to make a route unreachable. Those routes should be treated as bypassable unless running a release containing the fix.

4

Which releases contain the fix?

The issue is patched in Fastify 5.12.2 and is also included in the 6.0.0 release. The fix compiles and enforces boolean false and true schemas, including the query alias.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203