THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-84504 (HIGH 8.1) — fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request

[NVD] CVE-2026-84504 (HIGH 8.1) — fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request

mednvdPublished 2026-09-04

CVE-2026-84504 CVSS: 8.1 HIGH Published: 2026-09-04T10:17:13.790

fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request body with that property's value before the handler ru

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84504