Npm · Fastify · CVE-2026-92081
**Name of the Vulnerable Software and Affected Versions**
fastify versions prior to 5.12.5
**Description**
When a route registers a response trailer using the `reply.trailer()` function and is served over HTTP/2, the framework unconditionally sets the Transfer-Encoding: chunked header. Because this header is forbidden in HTTP/2, Node.js throws an exception during the serialization of response headers. This exception is not caught, resulting in an uncaughtException that crashes the server process and drops all in-flight requests. A single unauthenticated HTTP/2 request to any route utilizing trailers can trigger this crash, which can be repeated after every server restart.
**Recommendations**
Update to version 5.12.5 or later.
As a temporary workaround, avoid registering response trailers with the `reply.trailer()` function on routes served over HTTP/2.