OSS Support Hub / Web Framework

Node.js Web Framework MIT Latest: v5.8.5

Fastify

Fast and low overhead web framework for Node.js

Project Health at a Glance

Live data from GitHub and npm, updated daily.

โญ
36.2K+5
GitHub Stars
๐Ÿ“ฆ
v5.8.5
Latest Release ยท 1 months ago
๐Ÿ”„
10d
Avg. Release Cadence
๐Ÿ›
136
Open Issues
๐Ÿ“…
Yesterday
Last Commit
โฌ‡๏ธ
7.5M
Weekly Downloads
๐Ÿ”’
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header

Published: 2026-04-15 Fixed in: 5.8.5

Fastify: Incorrect Content-Type parsing can lead to CSRF attack

Published: 2022-11-21 Fixed in: 4.10.2

fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections

Published: 2026-03-25 Fixed in: 5.8.3

fastify vulnerable to denial of service via malicious Content-Type

Published: 2022-10-11 Fixed in: 4.8.1

Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation

Published: 2026-03-05 Fixed in: 5.8.1

Fastify's Content-Type header tab character allows body validation bypass

Published: 2026-02-02 Fixed in: 5.7.2

Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass

Published: 2025-04-18 Fixed in: 5.3.2

Denial of Service vulnerability with large JSON payloads in fastify

Published: 2018-07-18 Fixed in: 0.38.0

Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream

Published: 2026-02-02 Fixed in: 5.7.3

Denial of service in fastify

Published: 2020-08-05 Fixed in: 2.15.1

Alternatives to Fastify

Other Web Framework projects in the Node.js ecosystem worth evaluating.

Support Options for Fastify

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Fastify โ€” without relying on volunteer maintainers.

Talk to an Expert โ†’