Listen to this Post
Fastify runs a route’s validator and, for a result shaped like { value, error }, unwraps it: an error becomes a validation failure and value replaces the request part. This convention is intended for synchronous custom compilers (for example Joi). A JSON Schema `$async` validator, however, resolves with the validated data itself, so Fastify applied the same unwrapping to it. If a request part validated by an `$async` schema contains a `value` property, Fastify replaced the whole request part with that nested value before the handler ran, so a `value` or `error` property in the payload was attacker-controlled. An application that dispatches operations from the validated request body could then act on data that never satisfied the route schema, leading to unauthorized state changes or disclosure. Reaching the vulnerable path requires the route to use an `$async` request schema. The root cause is an improper handling of asynchronous validation results, where Fastify failed to distinguish between the synchronous custom-compiler contract and the asynchronous `$async` validator contract. This oversight allows a low-privileged authenticated attacker to manipulate the request body by including a `value` property, effectively replacing the validated data with attacker-controlled content. The CVSS v3.1 base score is 8.1 (High), with a vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N. The weakness is classified as CWE-20 (Improper Input Validation).
DailyCVE Form:
Platform: Fastify
Version: < 5.12.2
Vulnerability: Improper input validation
Severity: High (8.1)
date: 2026-09-04
Prediction: 2026-09-30
What Undercode Say:
Check installed Fastify version
npm list fastify
Inspect route schema for $async usage
grep -r '\$async' ./routes
Test validation behavior with a value property
curl -X POST http://localhost:3000/api/endpoint \
-H "Content-Type: application/json" \
-d '{"value": {"injected": true}}'
// Vulnerable route pattern
fastify.post('/vulnerable', {
schema: {
body: {
$async: true,
type: 'object',
properties: {
value: { type: 'object' }
}
}
}
}, async (request, reply) => {
// request.body may be replaced by the nested value
return { received: request.body };
});
Exploit: (Educational Purposes!)
Exploit: replace validated body with nested value
curl -X POST http://target/api/endpoint \
-H "Content-Type: application/json" \
-d '{"value": {"role": "admin", "action": "delete"}}'
Protection: from this CVE
Upgrade Fastify to 5.12.2 or 6.0.0. If immediate upgrade is not possible, avoid `$async` request schemas entirely. Perform security-sensitive checks in `onRequest` or `preHandler` hooks rather than relying on the schema-validated request part. Custom async validator compilers should signal failure by throwing (rejecting) an error instead of returning an `{ error }` object.
Impact:
Unauthorized state changes, data disclosure, privilege escalation, and bypass of route schema validation. An authenticated low-privilege caller can make nested data replace the validated body and trigger operations the route schema did not authorize.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

