Medium · 4.5 Node.js & npm GHSA-4mh8-r7rc-xpvc CVE-2026-92081
fastify Denial-of-Service Flaw: Unhandled Exception Crashes HTTP/2 Servers (CVE-2026-92081)
A vulnerability in fastify before version 5.12.5 lets an unauthenticated attacker crash the server process with a single HTTP/2 request to any route that uses response trailers. Upgrade to 5.12.5 or later, or avoid reply.trailer() on HTTP/2 routes until patched.
AI summary
A denial-of-service vulnerability has been identified in fastify, a popular Node.js web framework, tracked as CVE-2026-92081 (GHSA-4mh8-r7rc-xpvc). The issue affects routes that use response trailers when served over HTTP/2, and can cause the entire server process to crash from a single, unauthenticated request. A fix is available in fastify 5.12.5.
What happened
A vulnerability was disclosed in fastify affecting routes that register a response trailer using reply.trailer() when served over HTTP/2. In versions before 5.12.5, fastify unconditionally sets the Transfer-Encoding: chunked header on such responses. This header is forbidden under the HTTP/2 protocol, causing Node.js to throw an exception while serializing the response headers. Because the exception is not caught, it becomes an uncaught exception that crashes the entire server process, terminating all in-flight requests in the process.
Technical cause
The root cause is an uncaught exception (CWE-248) triggered by a protocol violation: fastify sets the Transfer-Encoding: chunked header regardless of the underlying HTTP version, but HTTP/2 explicitly forbids this header. Node.js's HTTP/2 implementation throws when attempting to serialize response headers containing this forbidden field, and fastify does not catch this exception, allowing it to propagate and crash the process.
Why it matters
A single, unauthenticated HTTP/2 request to any route using response trailers is sufficient to crash a vulnerable fastify server. Since the process terminates, all in-flight requests at the time of the crash are dropped, and the attack can be repeated after every restart, enabling a persistent and low-effort denial-of-service condition.
Who is affected
Any application built on fastify versions prior to 5.12.5 that serves traffic over HTTP/2 and uses reply.trailer() to register response trailers on one or more routes is affected.
Affected versions
fastify versions from 0 up to, but not including, 5.12.5 are affected.
Fixes and mitigation
The issue is fixed in fastify version 5.12.5. Users should upgrade to 5.12.5 or later. As a temporary workaround, avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until the upgrade can be applied.
Recommended action
Upgrade affected fastify installations to version 5.12.5 or later as soon as possible. If immediate upgrading is not feasible, remove or avoid reply.trailer() calls on any route that is served over HTTP/2 as an interim mitigation.
PatchBriefing score
4.5 / 10 · Medium
Official CVSS: 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
This vulnerability has a CVSS base score of 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H), reflecting a network-exploitable issue requiring no privileges or user interaction, with high impact on availability but none on confidentiality or integrity. The attack complexity is rated high because exploitation requires the specific combination of HTTP/2 and response trailers. PatchBriefing assigns an overall score of 4.5, factoring in the unauthenticated, no-interaction nature of the attack and fastify's broad adoption, offset by the absence of known exploitation, public exploit code, or EPSS-based high likelihood of exploitation.
Affected versions
- fastify < 5.12.5
- vulnerable
- ≥ 5.12.5
- patched
Reported fixes
The issue is fixed in fastify version 5.12.5. Users should upgrade to 5.12.5 or later. As a temporary workaround, avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until the upgrade can be applied.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email