Skip to content

chore(fastify): Update dependency fastify to v5.12.5 [SECURITY] - #10058

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-fastify-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-fastify-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
fastify (source) 5.8.5 → 5.12.5 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count

CVE-2026-16732 / GHSA-3m5p-2c4r-xxw2

More information

Details

Impact

The fix for CVE-2026-3635 (GHSA-444r-cwp2-x5xf) added a proxyFn(socket.remoteAddress, 0) guard on the X-Forwarded-* reads in request.host, request.protocol, request.hostname, request.ip, and request.ips. That guard closes the IP, CIDR, and custom-function forms of trustProxy correctly because those forms compile to predicates that inspect the connecting address. The hop-count form (trustProxy: <number>) compiles to a predicate that structurally ignores the address argument, so the guard reduces to 0 < tp, always true for any tp >= 1.

Applications configured with trustProxy: <number> (documented as "behind N reverse proxies", trustProxy: 1 being the canonical single-proxy setting) remain vulnerable. An attacker who can reach the Fastify origin directly, bypassing the front-facing proxy, can spoof the request fields exactly as in the unpatched version. Impact class matches the parent CVE-2026-3635: host injection in generated URLs, HTTPS-enforcement bypass, secure-cookie / CSRF-origin bypass, host-based routing and cache poisoning.

Patches

Patched in fastify 5.12.1. The numeric form of trustProxy is now disabled at runtime and removed from the TypeScript type union.

Workarounds
  • Migrate to an IP / CIDR / custom-function trustProxy value that validates the connecting address. Custom functions must inspect the address argument, not only the hop index.
  • Ensure the Fastify origin is only reachable through the trusted proxy chain (no direct network path).

Severity

  • CVSS Score: 6.1 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


fastify vulnerable to schema validation bypass via root primitive coercion mismatch

CVE-2026-18504 / GHSA-w2qp-rph6-63g4

More information

Details

Impact

fastify before 5.12.1, when a route uses a root-level primitive body schema (for example an integer with a minimum and maximum) and the default type coercion, validates the coerced value but exposes the original, uncoerced value to the route handler. For example, a JSON body "10" is coerced to the number 10 and passes an integer 1 to 10 schema, but request.body stays the string "10". An application that trusts the validated type is handed a value that did not satisfy the schema, which can bypass limits the application enforces on that typed value. Object and array body schemas are not affected, they coerce their members in place.

Patches

Upgrade to fastify 5.12.1.

Workarounds

Until you can upgrade, avoid relying on the validated type of a root primitive body. Wrap the value in an object schema (object properties are coerced in place), for example accept { "value": 10 } and read request.body.value, or re-check the type in the handler.

Severity

  • CVSS Score: 5.4 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


fastify vulnerable to header validation bypass via incomplete schema case normalization

CVE-2026-84428 / GHSA-9q9j-q6p8-xq58

More information

Details

Impact

Fastify lowercases header-schema property names before compiling the schema, because Node.js stores request header names in lowercase. That normalization was incomplete: it lowercased only top-level properties keys and the root required array, and did not lowercase the JSON Schema Draft 7 dependencies keyword (its trigger keys and dependent property names) or names in nested subschemas. As a result, a header schema that uses dependencies to require one header when another is present (for example X-Admin requiring X-Admin-Token) never matches the lowercased request headers, so the dependency assertion is silently skipped. An unauthenticated remote client can send the header that activates a privileged path while omitting the header the dependency was meant to require, bypassing a schema-enforced security control. The header schema is idiomatic, valid JSON Schema Draft 7, and no custom validator, malformed request, or misconfiguration is required.

Patches

Header-schema names are now normalized across all schema positions (properties, required, dependencies, dependentRequired, dependentSchemas, and nested subschemas). Patched in fastify 5.12.2. The fix is also included in the 6.0.0 release. Header schemas referenced through an external shared $ref (registered with addSchema) are not reached by this normalization and now emit an FSTSEC002 startup warning; inline the header schema to keep case-insensitive assertions in effect.

Workarounds

If upgrading is not immediately possible, write header-schema names in lowercase so the dependencies and other case-sensitive assertions match Node's lowercased request headers, or enforce the cross-header requirement in an onRequest or preValidation hook instead of the schema.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


fastify vulnerable to request validation bypass via skipped boolean false schemas

CVE-2026-84469 / GHSA-hwr6-493r-vm6h

More information

Details

Impact

Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance, but because false is falsy, a route that set body, querystring, params, or headers to false had that part left uncompiled: no validator was attached and the request reached the handler. An application that used false as a deny-all schema to make a route unreachable was therefore fully bypassed, and an unauthenticated remote client could reach the handler with any input. The same applied to the documented query alias for querystring. This is a complete bypass rather than a weak-schema issue, since false is the strongest JSON Schema assertion and must always fail.

Patches

Request-part schemas are now selected by an explicit presence check rather than truthiness, so a boolean false (or true) schema is compiled and enforced, including through the query alias. Patched in fastify 5.12.2. The fix is also included in the 6.0.0 release.

Workarounds

If upgrading is not immediately possible, express a deny-all request schema with an always-failing object schema instead of the boolean false (for example { "not": {} }), or reject the request in an onRequest hook.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers

CVE-2026-76169 / GHSA-p68q-wchp-6fh7

More information

Details

Impact

Fastify routes a malformed URL under one plugin prefix to the custom not-found handler of a different sibling plugin, invoking the handler registered last and skipping the preHandler declared in its setNotFoundHandler(). When the request method has no route in the main router, a malformed request target reaches Fastify's internal not-found router before URL decoding and is dispatched through a single shared handler pointer, regardless of prefix and without the normal request lifecycle. An unauthenticated request to a public prefix can therefore reach an authentication-protected not-found handler registered under a different prefix and receive its full response, breaking prefix encapsulation and bypassing the authentication hook. Applications whose private or tenant fallbacks return protected data from a not-found handler are affected.

Patches

Patched in fastify 5.12.2. Malformed URLs are now routed through the configured onBadUrl and onMaxParamLength handlers so they fail closed before any application not-found handler runs, and the shared not-found handler pointer has been removed.

Workarounds

Reject malformed request targets before they reach the application, for example at an upstream proxy or gateway, and do not rely on a not-found handler to serve protected data. A global onRequest authentication hook does not mitigate this, because the malformed-URL path skips it.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


fastify vulnerable to request body replacement via an async validation result collision

CVE-2026-84504 / GHSA-667r-xxjv-c9mm

More information

Details

Impact

Fastify runs a route's validator and, for a result shaped like { value, error }, unwraps it: an error becomes a validation failure and value replaces the request part. This convention is intended for synchronous custom compilers (for example Joi). A JSON Schema $async validator, however, resolves with the validated data itself, so Fastify applied the same unwrapping to it. If a request part validated by an $async schema contains a value property, Fastify replaced the whole request part with that nested value before the handler ran, so a value or error property in the payload was attacker-controlled. An application that dispatches operations from the validated request body could then act on data that never satisfied the route schema, leading to unauthorized state changes or disclosure. Reaching the vulnerable path requires the route to use an $async request schema.

Patches

Fastify no longer treats an asynchronous validation result as a { value, error } wrapper: an async validator's resolved value is used only to determine pass or fail, and it can no longer replace the request part or inject an error. The synchronous custom-compiler contract is unchanged. Patched in fastify 5.12.2 and 6.0.0.

Workarounds

If upgrading is not immediately possible, avoid $async request schemas, or perform the security-sensitive check in an onRequest or preHandler hook rather than relying on the schema-validated request part. Custom async validator compilers should signal failure by throwing (rejecting) rather than returning an { error } object.

Severity

  • CVSS Score: 8.1 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses

CVE-2026-92081 / GHSA-4mh8-r7rc-xpvc

More information

Details

Impact

fastify crashes with an uncaught ERR_HTTP2_INVALID_CONNECTION_HEADERS exception when a route that registers a response trailer via reply.trailer() is served over HTTP/2. Fastify unconditionally adds the Transfer-Encoding: chunked header when a trailer is set, which is forbidden on HTTP/2, so Node.js throws while serializing the response headers. The exception is not caught and becomes an uncaughtException, terminating the Node.js process.

One unauthenticated HTTP/2 request to any route that uses trailers is enough to crash the server, dropping all in-flight requests, and the request can be repeated to keep the process down. Applications are affected only when HTTP/2 is enabled (http2: true) and at least one route registers a trailer. HTTP/1.x responses are not affected.

Patches

Upgrade to fastify 5.12.5 or later.

Workarounds

Avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until upgrading.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

fastify/fastify (fastify)

v5.12.5

Compare Source

⚠️ Security release

What's Changed

Full Changelog: fastify/fastify@v5.12.4...v5.12.5

v5.12.4

Compare Source

Fixed the fastify.js version mismatch.

Full Changelog: fastify/fastify@v5.12.2...v5.12.4

v5.12.3

Compare Source

v5.12.2

Compare Source

⚠️ Security release

What's Changed

Full Changelog: fastify/fastify@v5.12.1...v5.12.2

v5.12.1

Compare Source

⚠️ Security release

What's Changed

Full Changelog: fastify/fastify@v5.12.0...v5.12.1

v5.12.0

Compare Source

What's Changed

Full Changelog: fastify/fastify@v5.11.3...v5.12.0

v5.11.3

Compare Source

What's Changed

New Contributors

Full Changelog: fastify/fastify@v5.11.2...v5.11.3

v5.11.2

Compare Source

v5.11.1

Compare Source

What's Changed

New Contributors

Full Changelog: fastify/fastify@v5.11.0...v5.11.1

v5.11.0

Compare Source

What's Changed

New Contributors

Full Changelog: fastify/fastify@v5.10.0...v5.11.0

v5.10.0

Compare Source

v5.9.0

Compare Source

What's Changed

New Contributors

Full Changelog: fastify/fastify@v5.8.5...v5.9.0


Configuration

📅 Schedule: (in timezone GMT)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 3, 2026
@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 3, 2026 11:13pm UTC
swingset Ready Ready Preview Oct 3, 2026 11:13pm UTC

Request Review

@renovate
renovate Bot enabled auto-merge (squash) October 3, 2026 23:10
@renovate

renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
.../electron-passkeys/npm/darwin-arm64   |  WARN  Unsupported platform: wanted: {"cpu":["arm64"],"os":["darwin"],"libc":["any"]} (current: {"os":"linux","cpu":"x64","libc":"glibc"})
.../electron-passkeys/npm/darwin-x64     |  WARN  Unsupported platform: wanted: {"cpu":["x64"],"os":["darwin"],"libc":["any"]} (current: {"os":"linux","cpu":"x64","libc":"glibc"})
.../npm/win32-arm64-msvc                 |  WARN  Unsupported platform: wanted: {"cpu":["arm64"],"os":["win32"],"libc":["any"]} (current: {"os":"linux","cpu":"x64","libc":"glibc"})
.../electron-passkeys/npm/win32-x64-msvc |  WARN  Unsupported platform: wanted: {"cpu":["x64"],"os":["win32"],"libc":["any"]} (current: {"os":"linux","cpu":"x64","libc":"glibc"})
Scope: all 33 workspace projects
Progress: resolved 1, reused 0, downloaded 0, added 0
packages/clerk-js                        |  WARN  deprecated crypto-js@4.2.0
packages/eslint-plugin                   |  WARN  deprecated eslint@9.31.0
packages/express                         |  WARN  deprecated supertest@6.3.4
Progress: resolved 81, reused 0, downloaded 0, added 0
Progress: resolved 190, reused 0, downloaded 0, added 0
Progress: resolved 303, reused 0, downloaded 0, added 0
Progress: resolved 477, reused 0, downloaded 0, added 0
Progress: resolved 660, reused 0, downloaded 0, added 0
Progress: resolved 1104, reused 0, downloaded 0, added 0
Progress: resolved 1366, reused 0, downloaded 0, added 0
Progress: resolved 1592, reused 0, downloaded 0, added 0
Progress: resolved 1912, reused 0, downloaded 0, added 0
Progress: resolved 2270, reused 0, downloaded 0, added 0
Progress: resolved 2440, reused 0, downloaded 0, added 0
Progress: resolved 2661, reused 0, downloaded 0, added 0
Progress: resolved 2942, reused 0, downloaded 0, added 0
Progress: resolved 2957, reused 0, downloaded 0, added 0
Progress: resolved 2997, reused 0, downloaded 0, added 0
Progress: resolved 3091, reused 0, downloaded 0, added 0
/tmp/renovate/repos/github/clerk/javascript/packages/expo:
 ERR_PNPM_TRUST_DOWNGRADE  High-risk trust downgrade for "fast-xml-parser@4.5.7" (possible package takeover)

This error happened while installing the dependencies of @react-native-community/cli@12.3.7
 at @react-native-community/cli-doctor@12.3.7
 at @react-native-community/cli-platform-ios@12.3.7

Trust checks are based solely on publish date, not semver. A package cannot be installed if any earlier-published version had stronger trust evidence. Earlier versions had trusted publisher, but this version has no trust evidence. A trust downgrade may indicate a supply chain incident.

@changeset-bot

changeset-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 5a29bb3

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 16c7fdbd-828d-4043-9c69-f3e201bc91a7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@10058

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@10058

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@10058

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@10058

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@10058

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@10058

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@10058

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@10058

@clerk/expo-biometrics

npm i https://pkg.pr.new/@clerk/expo-biometrics@10058

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@10058

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@10058

@clerk/express

npm i https://pkg.pr.new/@clerk/express@10058

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@10058

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@10058

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@10058

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@10058

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@10058

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@10058

@clerk/react

npm i https://pkg.pr.new/@clerk/react@10058

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@10058

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@10058

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@10058

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@10058

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@10058

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@10058

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@10058

commit: 5a29bb3

This branch was successfully deployed

2 active deployments
Preview – swingset — 5a29bb3b Deployed Oct 3, 2026 by vercel[bot]
Preview – clerk-js-sandbox — 5a29bb3b Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants