VYPR
Medium severity6.5NVD Advisory· Published Jul 30, 2020· Updated Jun 17, 2026

CVE-2020-8192

CVE-2020-8192

Description

A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
fastifynpm
< 2.15.12.15.1

Affected products

4
  • Fastify/Fastify3 versions
    cpe:2.3:a:fastify:fastify:2.14.1:*:*:*:*:node.js:*:*+ 2 more
    • cpe:2.3:a:fastify:fastify:2.14.1:*:*:*:*:node.js:*:*
    • cpe:2.3:a:fastify:fastify:3.0.0:rc4:*:*:*:node.js:*:*
    • (no CPE)
  • ghsa-coords
    Range: < 2.15.1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.