Executive brief
Fastify is a popular Node.js web framework used to build fast APIs and web applications. A vulnerability in versions 2.14.1 and 3.0.0-rc.4 allows attackers to cause resource exhaustion and service outages by sending specially crafted schema validation requests when the allErrors option is enabled. This could impact the availability and responsiveness of web services built on affected Fastify versions.
Technical details
The vulnerability is a resource exhaustion / denial-of-service condition in Fastify's JSON schema validation logic, specifically when the allErrors option is enabled in the Ajv validator configuration. An attacker can craft malicious schemas that trigger excessive validation error collection, consuming CPU and memory resources. The attack requires no authentication and is network-reachable; the attacker needs only to send HTTP requests with payloads that match the vulnerable schema patterns. The impact is service degradation or complete unavailability. The fix disables allErrors in the default Ajv configuration (patched in 2.15.1).
Affected products
- Fastify fastify 0 through 2.15.0, 3.0.0-rc.1 through 3.0.0-rc.4
Timeline
- 2020-08-05: disclosed
- 2020-08-05: patched: Fastify 2.15.1 released with fix