Executive brief
Fastify is a popular web framework for Node.js used to build web applications and APIs. A vulnerability in how it handles request headers could allow an attacker to trick a user's browser into sending unauthorized requests to a web application. This could result in actions being performed on behalf of a user without their consent, potentially compromising user accounts or data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Fastify due to incorrect parsing of the Content-Type header. An attacker can craft requests with specific Content-Type values (such as application/x-www-form-urlencoded, multipart/form-data, or text/plain) that bypass browser pre-flight (OPTIONS) checks but are still processed by Fastify routes intended only for application/json. This allows an attacker to bypass Cross-Origin Resource Sharing (CORS) protections and execute unauthorized state-changing requests. The issue is fixed in versions 3.29.4 and 4.10.2. Users are advised to upgrade or implement the @fastify/csrf plugin as a workaround.
Affected products
- Fastify fastify >=3.0.0, <3.29.4; >=4.0.0, <4.10.2
Timeline
- 2022-11-21: advisory: GitHub Security Advisory published
- 2022-11-21: patched: Fix committed to repository