216.73.216.226

CVE-2026-33806

· Published 15/04/2026 04:17 · Modified 15/04/2026 04:17

Labels: CVE-2026-33806 2026-04-15CVE-2026-33806CWE-1287ce714d77-add3-4f53-aff5-83d477b104bb

Essential information

Published
15/04/2026 04:17
Modified
15/04/2026 04:17
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS metrics

Description

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.3.2 by the fix for CVE-2025-32442 Patches: Upgrade to fastify v5.8.5 or later. Workarounds: None. Upgrade to the patched version.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ce714d77-add3-4f53-aff5-83d477b104bb
NVD
View on NVD

Affected products (CPE)

ProductCPE
fastify / fastify cpe:2.3:a:fastify:fastify:5.8.5:*:*:*:*:*:*:*

References