Loading HuntDB...

GHSA-mq6c-fh97-4gwv

GitHub Security Advisory

Denial of Service vulnerability with large JSON payloads in fastify

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Affected versions of `fastify` are vulnerable to a denial of service when processing a request with `Content-Type` set to `application/json` and a very large payload.

## Recommendation

Update to version 0.38.0 or later.

Affected Packages

npm fastify
Affected versions: 0 (fixed in 0.38.0)

Related CVEs

Key Information

GHSA ID
GHSA-mq6c-fh97-4gwv
Published
July 18, 2018 9:20 PM
Last Modified
March 1, 2023 1:17 AM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
fastify
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.