THREAT OPS › Threat News › [NVD] CVE-2026-84428 (HIGH 7.5) — fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level required array, and does not l
[NVD] CVE-2026-84428 (HIGH 7.5) — fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level required array, and does not l
CVE-2026-84428 CVSS: 7.5 HIGH Published: 2026-09-04T11:17:19.317
fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level required array, and does not lowercase the trigger and dependent names inside the JS
Indicators of compromise
- CVE-2026-84428cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84428