VYPR

Vendor CVEs

Fastify

All CVEs

102 total · sorted by risk
  • CVE-2022-29220MedMay 31, 2022
    risk 0.00cvss 6.5epss 0.00

    github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-action-merge-dependabot does not check if a commit created by dependabot is verified with the proper GPG key. There is just a check…

  • CVE-2021-29624MedMay 19, 2021
    risk 0.00cvss 6.5epss 0.01

    fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fastify-csrf prior to 3.1.0 have a "double submit" mechanism using cookies with an application deployed across multiple subdomains, e.g. "heroku"-style platform…

Page 3 of 3