CVE-2026-3419 Details
Description
Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in violation of RFC 9110 §8.3.1(https://httpwg.org/specs/rfc9110.html#field.content-type). For example, a request sent with Content-Type: application/json garbage passes validation and is processed normally, rather than being rejected with 415 Unsupported Media Type. When regex-based content-type parsers are in use (a documented Fastify feature), the malformed value is matched against registered parsers using the full string including the trailing garbage. This means a request with an invalid content-type may be routed to and processed by a parser it should never have reached. Impact: An attacker can send requests with RFC-invalid Content-Type headers that bypass validity checks, reach content-type parser matching, and be processed by the server. Requests that should be rejected at the validation stage are instead handled as if the content-type were valid. Workarounds: Deploy a WAF rule to protect against this Fix: The fix is available starting with v5.8.1.
A vulnerability exists in Fastify versions 5.7.2 prior to 5.8.1, where the framework improperly validates 'Content-Type' headers. The issue arises because Fastify's regex for subtypes in content types lacks an end anchor, allowing headers with trailing characters to be accepted as valid. This behavior contradicts RFC 9110 §8.3.1, which specifies the correct formatting for content types. As a result, requests with malformed 'Content-Type' headers can bypass validation and be processed by the server, potentially leading to incorrect routing in applications that use regex-based content-type parsers.
Users can upgrade to Fastify version 5.8.1 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cna.openjsf.org/security-advisories.html | openjs | Vendor Advisory |
| https://github.com/advisories/GHSA-573f-x89g-hqp9 | openjs | PatchVendor Advisory |
| https://github.com/fastify/fastify/commit/67f6c9b32cb3623d3c9470cc17ed830dd2f083d7 | openjs | Patch |
| https://github.com/fastify/fastify/security/advisories/GHSA-573f-x89g-hqp9 | openjs | Vendor Advisory |
| https://httpwg.org/specs/rfc9110.html#field.content-type | openjs | Technical Description |
| https://www.cve.org/CVERecord?id=CVE-2026-3419 | openjs | VDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-185 | Incorrect Regular Expression | openjs |
Affected Products
| Product | Versions |
|---|---|
| fastify fastify | >= 5.7.2, < 5.8.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | openjs |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 18, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | New CVE Received | openjs |