GHSA-mq6c-fh97-4gwv
Dashboard / Vulnerabilities / GHSA-mq6c-fh97-4gwv
Summary: Denial of Service vulnerability with large JSON payloads in fastify
Details: Affected versions of `fastify` are vulnerable to a denial of service when processing a request with `Content-Type` set to `application/json` and a very large payload. ## Recommendation Update to version 0.38.0 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-3711, https://github.com/fastify/fastify/pull/627, https://github.com/fastify/fastify/commit/fabd2a011f2ffbb877394abe699f549513ffbd76, https://hackerone.com/reports/303632, https://github.com/advisories/GHSA-mq6c-fh97-4gwv, https://www.npmjs.com/advisories/564
Affected packages
Package
Name: fastify
Purl: pkg:npm/fastify
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.38.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
