Vulnerability record · CVE-2022-39288 · published 10 October 2022
CVE-2022-39288: Fastify denial of service via malformed Content-Type header
Fastify · Fastify
Fastify, a Node.js web framework, mishandles invalid Content-Type headers, allowing a crafted request to crash the application. The flaw is a denial of service that requires no authentication and is trivially reachable over the network. It was fixed in commit fbb07e8d and release 4.8.1.
Description
fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of service via malicious use of the Content-Type header. An attacker can send an invalid Content-Type header that can cause the application to crash. This issue has been addressed in commit `fbb07e8d` and will be included in release version 4.8.1. Users are advised to upgrade. Users unable to upgrade may manually filter out http content with malicious Content-Type headers.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 high severity with network-reachable, unauthenticated denial of service and very high EPSS probability, though no KEV listing or confirmed in-the-wild exploitation is documented.
What it is
Fastify, a Node.js web framework, mishandles invalid Content-Type headers, allowing a crafted request to crash the application. The flaw is a denial of service that requires no authentication and is trivially reachable over the network. It was fixed in commit fbb07e8d and release 4.8.1.
Impact
An unauthenticated attacker can crash the Fastify process, causing service unavailability for all users of the affected application. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reachable remotely over HTTP by sending a request with a malformed Content-Type header to any endpoint that parses content type. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.59244 (99th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Fastify to version 4.8.1 or later, which includes the fix in commit fbb07e8d.
- If upgrade is not possible, manually filter or reject HTTP requests with malformed Content-Type headers before they reach Fastify.
- Deploy a reverse proxy or WAF rule that validates Content-Type headers and blocks malformed values.
- Monitor Fastify process crashes and restart behavior to detect exploitation attempts.
- Track the GitHub security advisory GHSA-455w-c45v-86rg for updated guidance.
Detection
- Monitor application logs for process crashes or unhandled exceptions correlated with incoming requests containing unusual Content-Type values.
- Inspect HTTP access logs for requests with malformed or non-standard Content-Type headers, especially repeated attempts from the same source.
- Alert on Fastify service restarts or availability gaps that coincide with spikes in malformed header traffic.
- Use WAF or proxy logs to identify and block sources sending invalid Content-Type headers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/fastify/fastify/commit/fbb07e8dfad74c69cd4cd2211aedab87194618e3 | PatchThird Party Advisory |
| https://github.com/fastify/fastify/security/advisories/GHSA-455w-c45v-86rg | MitigationThird Party Advisory |
| https://github.com/fastify/fastify/security/policy | Third Party Advisory |
| https://github.com/fastify/fastify/commit/fbb07e8dfad74c69cd4cd2211aedab87194618e3 | PatchThird Party Advisory |
| https://github.com/fastify/fastify/security/advisories/GHSA-455w-c45v-86rg | MitigationThird Party Advisory |
| https://github.com/fastify/fastify/security/policy | Third Party Advisory |
Track CVE-2022-39288 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-39288), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.