VYPR

@fastify/bearer-auth

by Fastify

Source repositories

CVEs (2)

  • CVE-2026-92087HigSep 16, 2026
    risk 0.46cvss 8.1epss 0.00

    @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the run "all" option and one entry is a…

  • CVE-2022-31142HigJul 14, 2022
    risk 0.42cvss 7.5epss 0.01

    @fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions 7.0.2 and 8.0.1 does not securely use crypto.timingSafeEqual. A malicious attacker could estimate the length of one valid bearer token. According to the…