Oct 1, 2026·7 min read·9 visits
Fastify fails to compile validation schemas configured as boolean 'false', causing 'deny-all' schemas to be completely ignored. Unauthenticated remote attackers can bypass payload validation and execute backend route handlers.
CVE-2026-84469 is a high-severity request validation bypass vulnerability in the Fastify Node.js web framework. In versions prior to 5.12.2, Fastify uses loose truthiness checks to decide whether to compile request schemas. When a component (such as the body) is explicitly configured with a boolean 'false' schema—which under JSON Schema Draft 7 acts as a 'deny-all' constraint—Fastify's internal logic evaluates this as a falsy value and skips compilation entirely. This allows unauthenticated remote attackers to send arbitrary payloads to these endpoints, bypassing validation checks and directly executing backend route handlers.
Fastify is a widely adopted, high-performance web framework for the Node.js ecosystem. It relies heavily on schema-based compilation to perform high-speed input validation and serialization. In Fastify, route definitions can incorporate explicit JSON Schemas to validate components of incoming HTTP requests, such as headers, query parameters, route parameters, and the body. These validation layers act as a primary security boundary, protecting the underlying handler logic from malformed or unexpected data structures.
Under the JSON Schema Draft 7 specification, a schema can be declared as a boolean value. While a schema of true allows any input, a schema of false acts as a strict "deny-all" constraint. Developers frequently employ false schemas to secure endpoints, ensuring that specific parts of a request, such as query parameters or POST request bodies, are completely disabled and rejected.
This vulnerability, cataloged as CVE-2026-84469, is a high-severity request validation bypass. It occurs because the framework evaluates schema definitions using loose JavaScript truthiness checks. Because the boolean false is falsy in JavaScript, Fastify treats an explicitly defined false schema as missing or omitted. Consequently, the compiler fails to register the validation logic, and the framework executes the target route handler with unvalidated client input.
The root cause of CVE-2026-84469 lies in how Fastify's internal initialization engine detects the presence of schema definitions within lib/route.js, lib/schemas.js, and lib/validation.js. During the registration phase of an HTTP route, Fastify constructs its validation architecture by checking for defined properties on the route configuration's schema object.
In vulnerable versions of Fastify, the framework used implicit JavaScript truthiness operators (such as opts.schema.body || opts.schema.headers or if (schema.body)) to establish whether a specific schema compiled. In JavaScript, several values are treated as "falsy", including false, 0, "", null, undefined, and NaN. Because the JSON Schema Draft 7 specification defines the literal boolean false as a valid "deny-all" schema, developers setting a schema block to false expected Fastify to compile a validator that rejects all incoming requests.
However, during execution, the falsy nature of false caused Fastify to bypass the initialization of the validation compiler. The conditional statement evaluated the explicitly defined schema as absent. As a result, the framework did not bind any validator to the request handler, allowing the engine to parse arbitrary client-supplied payloads and pass them directly to the backend handler.
To understand the structural flaw, we can examine the vulnerable implementation in lib/route.js and compare it with the updated logic applied in the official fix.
Prior to the patch, lib/route.js determined if a route required schema compilation using the following validation check:
// Vulnerable pattern in lib/route.js
const hasValidationSchema = opts.schema.body ||
opts.schema.headers ||
opts.schema.querystring ||
opts.schema.paramsIf a developer configured a route to reject all body content by specifying opts.schema.body = false, and did not specify other schemas, hasValidationSchema evaluated to false. This skipped the invocation of schemaController.setupValidator().
The official patch (7de6e81697778f9f41bd327a3b1c5c9a0d9637b4) resolved this by replacing the logical OR (||) checks with explicit undefined checks.
// Patched pattern in lib/route.js
const hasValidationSchema = opts.schema.body !== undefined ||
opts.schema.headers !== undefined ||
opts.schema.querystring !== undefined ||
opts.schema.params !== undefinedThis modification ensures that any value other than undefined—including the boolean false—is treated as a present schema configuration, forcing Fastify to initialize and execute the validation engine.
Exploitation of this vulnerability requires no specialized tools or prior authentication. It relies entirely on sending well-formed requests to routes that developers configured with boolean false schemas to block input.
Consider an application endpoint designed to trigger an action without receiving external parameters, such as a GET request that uses querystring: false to enforce strict isolation:
fastify.get('/api/trigger', {
schema: {
querystring: false
}
}, async (request, reply) => {
if (request.query.force === 'true') {
runPrivilegedTask();
}
return { status: "Success" };
});In a vulnerable Fastify instance, sending a request to /api/trigger?force=true bypasses the query parameter validation. Fastify skips compilation of the query parser's validator, processes the query parameter, populates the request.query object, and runs the handler. The handler executes runPrivilegedTask() because the input is processed without hindrance.
To verify this vulnerability, an attacker can transmit an arbitrary payload to a target route that explicitly restricts that request component. If the server processes the request with an HTTP 200 OK status and executes the corresponding backend code instead of returning an HTTP 400 Bad Request code, the application is confirmed to be vulnerable.
The security impact of CVE-2026-84469 is significant for applications that rely on schemas to enforce strict data boundaries or to disable specific operational features. While the vulnerability does not directly lead to remote code execution at the framework layer, it completely removes the input validation layer.
This bypass can lead to downstream vulnerabilities, such as SQL Injection, NoSQL Injection, or Path Traversal, if the target route handlers assume that the incoming input is pre-validated or entirely absent. For example, if a developer configures an endpoint with body: false and executes dangerous commands based on fields within the body (under the assumption that those fields can never reach the handler), an attacker can supply malicious payloads to trigger those operations.
The Common Vulnerability Scoring System (CVSS) v3.1 assigns this flaw a base score of 7.5 (High), reflecting a high integrity impact and low exploitation complexity. Because the attack requires no privileges or user interaction and can be executed remotely over the network, it presents an attractive vector for targeting applications that leverage boolean-based security configurations.
The primary and recommended mitigation is to update the Fastify dependency to version 5.12.2 or higher. This update alters the validation initialization path to perform strict presence checks rather than loose truthiness checks, ensuring that boolean schemas are correctly compiled and enforced.
If upgrading is not immediately possible, security teams can implement a temporary workaround by replacing all occurrences of false schemas with explicit validation schemas that reject all input. For instance, developers can configure the schema to reject any property by setting additionalProperties to false and requiring an impossible field:
schema: {
body: {
type: 'object',
properties: {
denyAllField: { type: 'string', minLength: 999999 }
},
required: ['denyAllField'],
additionalProperties: false
}
}An alternative workaround is the implementation of application-level hooks. A preValidation hook can be registered globally or on specific routes to inspect incoming payloads and manually reject them with an HTTP 400 response:
fastify.addHook('preValidation', async (request, reply) => {
if (request.body !== undefined && request.body !== null) {
reply.code(400).send({ error: 'Bad Request', message: 'Payloads are not permitted on this route' });
}
});The fix implemented in Fastify version 5.12.2 is structurally complete. By validating the presence of the schema properties using strict inequality operators (!== undefined), it completely covers all boolean values, preventing similar truthiness bypasses.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
Fastify Fastify | >= 0.1.0, < 5.12.2 | 5.12.2 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-20: Improper Input Validation |
| Attack Vector | Network (Remote) |
| CVSS Score | 7.5 (High) |
| EPSS Score | 0.00492 (Percentile: 39.86%) |
| Impact | Validation Bypass / Integrity Compromise |
| Exploit Status | PoC Available |
| KEV Status | Not Listed |
The product does not validate or incorrectly validates input that can affect the control flow or data flow of a program.
An authorization bypass and path traversal vulnerability exists in the SiYuan knowledge workspace platform. The vulnerability is located in the '/api/file/getUniqueFilename' endpoint inside the 'github.com/siyuan-note/siyuan/kernel' package. Under default configurations, this route is exposed to users who satisfy basic authentication middleware checks, which includes anonymous readers in publish mode. By supplying unvalidated absolute paths, remote attackers can verify the existence of files and directories across the host operating system, establishing a high-fidelity file existence oracle.
A highly critical Regular Expression Denial of Service (ReDoS) vulnerability in basic-ftp, an FTP client library for Node.js. In versions prior to 6.2.1, a malicious or compromised FTP server can exploit this vulnerability to force the FTP client to consume quadratic CPU time during directory parsing. This issue blocks the single-threaded Node.js event loop, freezing the application process and leading to a complete Denial of Service (DoS).
An uncontrolled resource consumption vulnerability in the russh library allows remote authenticated attackers to exhaust server memory (heap) by flooding channel open requests during a stalled key re-exchange (rekeying) process, causing a denial of service via Out-of-Memory (OOM) termination.
A critical memory handling vulnerability exists in the pageant crate, a workspace component of the Rust-based russh SSH client library, during communication with the PuTTY Pageant SSH agent on Windows systems. Prior to version 0.2.3, the library's shared memory parsing logic blindly trusted a peer-controlled, 32-bit big-endian response length field. This allows local attackers running within the same user session to trigger out-of-bounds reads or execute an out-of-memory crash of the client application.
A validation bypass vulnerability exists in Fastify web framework prior to version 5.12.2. The flaw stems from shallow normalization of header validation schemas, which fails to lowercase nested or conditional schema rules (like JSON Schema dependencies or dependentRequired) defined in mixed or canonical casing. Consequently, because Node.js normalizes incoming HTTP request headers to lowercase, the compiled validator fails to match these headers against the un-normalized mixed-case schema triggers, silently skipping conditional checks and allowing unauthenticated attackers to bypass authorization or security headers.
An authentication bypass vulnerability in the Fastify web framework allows remote attackers to access private custom not-found handlers by submitting requests with malformed URLs. This bypasses the typical request lifecycle and its associated authorization hooks.