Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.5 Node.js & npm GHSA-4mh8-r7rc-xpvc CVE-2026-92081

fastify Denial-of-Service Flaw: Unhandled Exception Crashes HTTP/2 Servers (CVE-2026-92081)

A vulnerability in fastify before version 5.12.5 lets an unauthenticated attacker crash the server process with a single HTTP/2 request to any route that uses response trailers. Upgrade to 5.12.5 or later, or avoid reply.trailer() on HTTP/2 routes until patched.

Synthesized by AI from 2 sources · updated 2 hours ago

AI summary

A denial-of-service vulnerability has been identified in fastify, a popular Node.js web framework, tracked as CVE-2026-92081 (GHSA-4mh8-r7rc-xpvc). The issue affects routes that use response trailers when served over HTTP/2, and can cause the entire server process to crash from a single, unauthenticated request. A fix is available in fastify 5.12.5.

What happened

A vulnerability was disclosed in fastify affecting routes that register a response trailer using reply.trailer() when served over HTTP/2. In versions before 5.12.5, fastify unconditionally sets the Transfer-Encoding: chunked header on such responses. This header is forbidden under the HTTP/2 protocol, causing Node.js to throw an exception while serializing the response headers. Because the exception is not caught, it becomes an uncaught exception that crashes the entire server process, terminating all in-flight requests in the process.

Technical cause

The root cause is an uncaught exception (CWE-248) triggered by a protocol violation: fastify sets the Transfer-Encoding: chunked header regardless of the underlying HTTP version, but HTTP/2 explicitly forbids this header. Node.js's HTTP/2 implementation throws when attempting to serialize response headers containing this forbidden field, and fastify does not catch this exception, allowing it to propagate and crash the process.

Why it matters

A single, unauthenticated HTTP/2 request to any route using response trailers is sufficient to crash a vulnerable fastify server. Since the process terminates, all in-flight requests at the time of the crash are dropped, and the attack can be repeated after every restart, enabling a persistent and low-effort denial-of-service condition.

Who is affected

Any application built on fastify versions prior to 5.12.5 that serves traffic over HTTP/2 and uses reply.trailer() to register response trailers on one or more routes is affected.

Affected versions

fastify versions from 0 up to, but not including, 5.12.5 are affected.

Fixes and mitigation

The issue is fixed in fastify version 5.12.5. Users should upgrade to 5.12.5 or later. As a temporary workaround, avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until the upgrade can be applied.

Recommended action

Upgrade affected fastify installations to version 5.12.5 or later as soon as possible. If immediate upgrading is not feasible, remove or avoid reply.trailer() calls on any route that is served over HTTP/2 as an interim mitigation.

PatchBriefing score

4.5 / 10 · Medium

Official CVSS: 5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

This vulnerability has a CVSS base score of 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H), reflecting a network-exploitable issue requiring no privileges or user interaction, with high impact on availability but none on confidentiality or integrity. The attack complexity is rated high because exploitation requires the specific combination of HTTP/2 and response trailers. PatchBriefing assigns an overall score of 4.5, factoring in the unauthenticated, no-interaction nature of the attack and fastify's broad adoption, offset by the absence of known exploitation, public exploit code, or EPSS-based high likelihood of exploitation.

Affected versions

fastify < 5.12.5
vulnerable
≥ 5.12.5
patched

Reported fixes

The issue is fixed in fastify version 5.12.5. Users should upgrade to 5.12.5 or later. As a temporary workaround, avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until the upgrade can be applied.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
fastify Denial-of-Service Flaw: Unhandled Exception Crashes HTTP/2 Servers (CVE-2026-92081)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email