
Cloud Vulnerability DB
A community-led vulnerabilities database
Fastify, a fast and low overhead web framework for Node.js, was found to contain a denial of service vulnerability (CVE-2022-39288) affecting versions >=4.0.0 <=4.8.0. The vulnerability was disclosed on October 10, 2022, and was patched in version 4.8.1 (NVD, GitHub Advisory).
The vulnerability allows attackers to cause a denial of service by sending malicious Content-Type headers that can crash the application. The issue received a CVSS v3.1 base score of 7.5 (High severity), with attack vector being Network, attack complexity Low, requiring no privileges or user interaction, and primarily impacting system availability (GitHub Advisory).
When successfully exploited, this vulnerability can lead to a denial of service condition, causing the application to crash and become unavailable. The impact is primarily focused on system availability, with no direct effect on confidentiality or integrity (GitHub Advisory).
The primary mitigation is to upgrade to Fastify version 4.8.1 or later. For those unable to upgrade immediately, a workaround is available by implementing a request hook that rejects malicious content types before the body parser processes them. This can be done by checking against known malicious patterns in the Content-Type header (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."