PT-2026-33000 · Npm · Fastify

·

CVE-2026-33806

·

Published

2025-04-18

·

Updated

2026-04-15

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions fastify versions 5.3.2 through 5.8.4
Description Applications using schema.body.content for per-content-type body validation are subject to a validation bypass. By prepending a space to the Content-Type header, the body is still parsed correctly, but the schema validation is skipped entirely.
Recommendations Upgrade to version 5.8.5 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09015
CVE-2026-33806
GHSA-247C-9743-5963
GHSA-MG2H-6X62-WPWC

Affected Products

Fastify