PT-2026-93404 · Npm · Fastify

·

CVE-2026-92081

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions fastify versions prior to 5.12.5
Description When a route registers a response trailer using the reply.trailer() function and is served over HTTP/2, the framework unconditionally sets the Transfer-Encoding: chunked header. Because this header is forbidden in HTTP/2, Node.js throws an exception during the serialization of response headers. This exception is not caught, resulting in an uncaughtException that crashes the server process and drops all in-flight requests. A single unauthenticated HTTP/2 request to any route utilizing trailers can trigger this crash, which can be repeated after every server restart.
Recommendations Update to version 5.12.5 or later. As a temporary workaround, avoid registering response trailers with the reply.trailer() function on routes served over HTTP/2.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92081
GHSA-4MH8-R7RC-XPVC

Affected Products

Fastify