Unrated severityNVD Advisory· Published Sep 4, 2026
fastify vulnerable to request validation bypass via skipped boolean false schemas
CVE-2026-84469
Description
fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's body, querystring, params, or headers schema to deny all input, fastify treats it as a missing schema, compiles no validator, and runs the route handler on any request. An unauthenticated remote client can therefore reach a handler that a valid deny-all schema was intended to make unreachable, a complete validation bypass that can lead to unauthorized state changes or execution of disabled operations. Users should upgrade to fastify 5.12.2 or later.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.