GHSA-9q9j-q6p8-xq58

Suggest an improvement
Source
https://github.com/advisories/GHSA-9q9j-q6p8-xq58
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9q9j-q6p8-xq58/GHSA-9q9j-q6p8-xq58.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9q9j-q6p8-xq58
Aliases
Published
2026-09-30T23:44:27Z
Modified
2026-10-01T00:00:04Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
fastify vulnerable to header validation bypass via incomplete schema case normalization
Details

Impact

Fastify lowercases header-schema property names before compiling the schema, because Node.js stores request header names in lowercase. That normalization was incomplete: it lowercased only top-level properties keys and the root required array, and did not lowercase the JSON Schema Draft 7 dependencies keyword (its trigger keys and dependent property names) or names in nested subschemas. As a result, a header schema that uses dependencies to require one header when another is present (for example X-Admin requiring X-Admin-Token) never matches the lowercased request headers, so the dependency assertion is silently skipped. An unauthenticated remote client can send the header that activates a privileged path while omitting the header the dependency was meant to require, bypassing a schema-enforced security control. The header schema is idiomatic, valid JSON Schema Draft 7, and no custom validator, malformed request, or misconfiguration is required.

Patches

Header-schema names are now normalized across all schema positions (properties, required, dependencies, dependentRequired, dependentSchemas, and nested subschemas). Patched in fastify 5.12.2. The fix is also included in the 6.0.0 release. Header schemas referenced through an external shared $ref (registered with addSchema) are not reached by this normalization and now emit an FSTSEC002 startup warning; inline the header schema to keep case-insensitive assertions in effect.

Workarounds

If upgrading is not immediately possible, write header-schema names in lowercase so the dependencies and other case-sensitive assertions match Node's lowercased request headers, or enforce the cross-header requirement in an onRequest or preValidation hook instead of the schema.

Database specific
{
    "cwe_ids": [
        "CWE-178"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-30T23:44:27Z",
    "nvd_published_at": "2026-09-04T11:17:19Z",
    "severity": "HIGH"
}
References

Affected packages

npm / fastify

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.12.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9q9j-q6p8-xq58/GHSA-9q9j-q6p8-xq58.json"