Executive brief
Fastify, a popular Node.js web framework, incorrectly accepts malformed Content-Type headers that violate HTTP standards. An attacker can send requests with invalid Content-Type headers (e.g., "application/json garbage") that bypass validation checks and reach content-type parsers they should be rejected by, potentially causing requests to be processed by unintended handlers. This could lead to security issues depending on how the application's request routing and parsing logic handles mismatched content types.
Technical details
The vulnerability is an incorrect regular expression (CWE-185) in Fastify's "subtypeNameReg" regex pattern used to validate Content-Type headers. The regex lacks an end anchor ($), allowing malformed Content-Type headers with trailing characters after the subtype token to pass validation. For example, "application/json garbage" is accepted instead of being rejected with HTTP 415 Unsupported Media Type. When regex-based content-type parsers are configured (a documented Fastify feature), the full malformed string—including trailing garbage—is matched against registered parsers. This can cause a request to be routed to and processed by a parser it should never have reached, violating RFC 9110 §8.3.1. The vulnerability affects Fastify versions >= 5.7.2 and <= 5.8.0; it was fixed in version 5.8.1. No authentication or user interaction is required; the attack is network-accessible.
Affected products
- Fastify fastify >= 5.7.2, <= 5.8.0
Timeline
- 2026-03-05: disclosed: GHSA-573f-x89g-hqp9 published
- 2026-03-05: patched: Fix available in v5.8.1