PT-2026-93404 · Npm · Fastify
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
fastify versions prior to 5.12.5
Description
When a route registers a response trailer using the
reply.trailer() function and is served over HTTP/2, the framework unconditionally sets the Transfer-Encoding: chunked header. Because this header is forbidden in HTTP/2, Node.js throws an exception during the serialization of response headers. This exception is not caught, resulting in an uncaughtException that crashes the server process and drops all in-flight requests. A single unauthenticated HTTP/2 request to any route utilizing trailers can trigger this crash, which can be repeated after every server restart.Recommendations
Update to version 5.12.5 or later.
As a temporary workaround, avoid registering response trailers with the
reply.trailer() function on routes served over HTTP/2.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastify