VYPR
Low severity3.7NVD Advisory· Published Feb 3, 2026· Updated Jun 17, 2026

CVE-2026-25224

CVE-2026-25224

Description

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applications that return a ReadableStream (or Response with a Web Stream body) via reply.send() are impacted. A slow or non-reading client can trigger unbounded buffering when backpressure is ignored, leading to process crashes or severe degradation. This issue has been patched in version 5.7.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
fastifynpm
< 5.7.35.7.3

Affected products

3
  • Fastify/Fastify2 versions
    cpe:2.3:a:fastify:fastify:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:fastify:fastify:*:*:*:*:*:node.js:*:*range: <5.7.3
    • (no CPE)range: < 5.7.3
  • ghsa-coords
    Range: < 5.7.3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.