Npm · Fastify · CVE-2026-33806
**Name of the Vulnerable Software and Affected Versions**
fastify versions 5.3.2 through 5.8.4
**Description**
Applications using `schema.body.content` for per-content-type body validation are subject to a validation bypass. By prepending a space to the Content-Type header, the body is still parsed correctly, but the schema validation is skipped entirely.
**Recommendations**
Upgrade to version 5.8.5 or later.