Fastify - HackerOne Reports
View on HackerOne4
Total Reports
0
Critical
1
High
1
Medium
1
Low
1-click DOS in fastify-static via directly passing user's input to new URL() of NodeJS without try/catch
Reported by:
drstrnegth
|
Disclosed:
Medium
Weakness: Uncontrolled Resource Consumption
Deny of service via malicious Content-Type
Reported by:
bitk
|
Disclosed:
High
Weakness: Uncontrolled Resource Consumption
Open redirect in fastify-static via mishandled user's input when attempt to redirect
Reported by:
drstrnegth
|
Disclosed:
Low
Weakness: Open Redirect
CVEs:
CVE-2015-1164