GHSA-455w-c45v-86rg

    Dashboard / Vulnerabilities / GHSA-455w-c45v-86rg

    GHSA-455w-c45v-86rg

    Published: 11 Oct 2022Last Modified: 8 Nov 2023

    Summary: fastify vulnerable to denial of service via malicious Content-Type

    Details: ### Impact An attacker can send an invalid `Content-Type` header that can cause the application to crash, leading to a possible Denial of Service attack. Only the v4.x line is affected. (This was updated: upon a close inspection, v3.x is not affected after all). ### Patches Yes, update to `> v4.8.0`. ### Workarounds You can reject the malicious content types before the body parser enters in action. ```js const badNames = Object.getOwnPropertyNames({}.__proto__) fastify.addHook('onRequest', async (req, reply) => { for (const badName of badNames) { if (req.headers['content-type'].indexOf(badName) > -1) { reply.code(415) throw new Error('Content type not supported') } } }) ``` ### References See the HackerOne report [#1715536](https://hackerone.com/bugs?report_id=1715536&subject=fastify) ### For more information [Fastify security policy](https://github.com/fastify/fastify/security/policy)

    Affected packages

    Package

    Name: fastify

    Purl: pkg:npm/fastify

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.0.0
    Fixed -4.8.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-455w-c45v-86rg | CVE-DB