ZÉROJOUR

The zero-day paper — printed from structured content, not scraped prose.
Permanent editionPublic dataset · Sanity GROQGHSA × CISA KEV
fastify (npm) · published 2026-09-02

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

CVE-2026-18504 — CVSS 5.4/10. Fix: upgrade to 5.12.1.
Package
fastify
Ecosystem
npm
Vector
NETWORK
Complexity
LOW
Privileges
LOW
Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Impact

`fastify` before 5.12.1, when a route uses a root-level primitive body schema (for example an integer with a minimum and maximum) and the default type coercion, validates the coerced value but exposes the original, uncoerced value to the route handler. For example, a JSON body `"10"` is coerced to the number `10` and passes an integer 1 to 10 schema, but `request.body` stays the string `"10"`. An application that trusts the validated type is handed a value that did not satisfy the schema, which can bypass limits the application enforces on that typed value. Object and array body schemas are not affected, they coerce their members in place.

Patches

Upgrade to `fastify` 5.12.1.

Workarounds

Until you can upgrade, avoid relying on the validated type of a root primitive body. Wrap the value in an object schema (object properties are coerced in place), for example accept `{ "value": 10 }` and read `request.body.value`, or re-check the type in the handler.

Weakness classes: CWE-20 (Improper Input Validation)

Source: GHSA-w2qp-rph6-63g4 · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page

ZéroJour prints itself from a Sanity dataset of real advisories (GitHub Advisory Database, CC-BY-4.0; CISA KEV). No scraping, no keyword search — headlines are typed fields, scores are numbers, fixes are versions. The newsroom composes, a human approves.