THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w2qp-rph6-63g4 (medium) — fastify vulnerable to schema validation bypass via root primitive coercion mismatch

[GHSA] GHSA-w2qp-rph6-63g4 (medium) — fastify vulnerable to schema validation bypass via root primitive coercion mismatch

medgithub_advisoriesPublished 2026-09-02

GHSA-w2qp-rph6-63g4 Severity: medium CVE: CVE-2026-18504

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

### Impact

`fastify` before 5.12.1, when a route uses a root-level primitive body schema (for example an integer with a minimum and maximum) and the default type coercion, validates the coerced value but exposes the original, uncoerced value to the route h

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w2qp-rph6-63g4