Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 27 SEP 2026

Fastify · AUTOMATIC DISCOVERY

Fastify 4.0.0

Fastify is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

Fastify is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductFastify
Release4.0.0
End of Support30 June 2025
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 1 Oct 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

No CISA known-exploited entries currently match this mapped product family.

This does not mean the product has no vulnerabilities.

Package vulnerability advisories

Checked 29 Sep 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2025-32442High severity

Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header

pkg:npm/fastifyFixed: 5.8.5

OSV record
CVE-2025-32442High severity

Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass

pkg:npm/fastifyFixed: 5.3.2, 4.29.1

OSV record
CVE-2026-25223High severity

Fastify's Content-Type header tab character allows body validation bypass

pkg:npm/fastifyFixed: 5.7.2

OSV record
CVE-2026-18504Medium severity

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

pkg:npm/fastifyFixed: 5.12.1

OSV record
CVE-2026-16732Medium severity

fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count

pkg:npm/fastifyFixed: 5.12.1

OSV record
CVE-2026-3419Medium severity

Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation

pkg:npm/fastifyFixed: 5.8.1

OSV record
CVE-2026-3635Medium severity

fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections

pkg:npm/fastifyFixed: 5.8.3

OSV record
CVE-2026-25224Low severity

Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream

pkg:npm/fastifyFixed: 5.7.3

OSV record

Source evidence

PRIMARYManual

Fastify official lifecycle source

Version | Release Date | End Of LTS Date | Node.js | Nsolid(Node) | 4.0.0 | 2022-06-08 | 2025-06-30 | 14, 16, 18, 20, 22 | v5(18), v5(20)

Publisher identity used by product-specific official-source collectors.

First collected 12 Sep 2026 · Last collected 27 Sep 2026 · Review state accepted

Open official vendor source