Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
PRODUCT FAMILYFRAMEWORKVERIFIED

Fastify

Fastify

Fastify is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Lifecycle status

No support or retirement date is shown unless BlackTree can link it to a registered publisher source. A missing date means that a boundary is not publicly stated, has not yet been extracted, or still needs source routing. It does not mean the product is supported indefinitely.

Product overview

Fastify is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

Lifecycle records

ReleaseBoundaryDate
1.0.0Support ends1 September 2019
2.0.0Support ends31 January 2021
3.0.0Support ends30 June 2023
4.0.0Support ends30 June 2025

Official sources

VERIFIED

Fastify official lifecycle source

Checked automatically.

Extracted 4 lifecycle record(s), including 4 bounded date record(s), from the registered official source.

Open publisher source

Package vulnerability advisories

Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header

Fixed: 5.8.5

Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass

Fixed: 5.3.2, 4.29.1

Fastify's Content-Type header tab character allows body validation bypass

Fixed: 5.7.2

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

Fixed: 5.12.1

fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count

Fixed: 5.12.1

Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation

Fixed: 5.8.1

fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections

Fixed: 5.8.3

Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream

Fixed: 5.7.3