PT-2022-24945 · Fastify · @Fastify/Websocket

Marcolanaro

·

Published

2022-11-07

·

Updated

2022-11-09

·

CVE-2022-39386

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions fastify-websocket versions prior to 7.1.1 (fastify v4) and prior to 5.0.1 (fastify v3) @fastify/websocket (all versions, deprecated)
Description Any application using @fastify/websocket could crash if a specific, malformed packet is sent. The issue has been patched in version 7.1.1 (fastify v4) and version 5.0.1 (fastify v3). There are currently no known workarounds, but it should be possible to attach the error handler manually.
Recommendations For fastify-websocket versions prior to 7.1.1 (fastify v4), upgrade to version 7.1.1 or later. For fastify-websocket versions prior to 5.0.1 (fastify v3), upgrade to version 5.0.1 or later. As a temporary workaround, consider attaching the error handler manually until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-39386
GHSA-4PCG-WR6C-H9CQ

Affected Products

@Fastify/Websocket