Junglewise Threat Intelligence

CVE-2022-41919: Fastify incorrect Content-Type parsing leads to CSRF

CVE-2022-41919 · Severity: low · CVSS 3.1 · Published 2022-11-21

Vendors: Fastify.

Executive brief

Fastify is a popular web framework for Node.js used to build web applications and APIs. A vulnerability in how it handles request headers could allow an attacker to trick a user's browser into sending unauthorized requests to a web application. This could result in actions being performed on behalf of a user without their consent, potentially compromising user accounts or data.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Fastify due to incorrect parsing of the Content-Type header. An attacker can craft requests with specific Content-Type values (such as application/x-www-form-urlencoded, multipart/form-data, or text/plain) that bypass browser pre-flight (OPTIONS) checks but are still processed by Fastify routes intended only for application/json. This allows an attacker to bypass Cross-Origin Resource Sharing (CORS) protections and execute unauthorized state-changing requests. The issue is fixed in versions 3.29.4 and 4.10.2. Users are advised to upgrade or implement the @fastify/csrf plugin as a workaround.

Affected products

  • Fastify fastify >=3.0.0, <3.29.4; >=4.0.0, <4.10.2

Timeline

  • 2022-11-21: advisory: GitHub Security Advisory published
  • 2022-11-21: patched: Fix committed to repository

References