CVE-2026-92081
Received Received - Intake

HTTP/2 Header Error in Fastify Framework

Vulnerability report for CVE-2026-92081, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: openjs

Description

fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fastify unconditionally sets the Transfer-Encoding: chunked header, which is forbidden on HTTP/2, so Node.js throws while serializing the response headers. The exception is not caught and becomes an uncaughtException, so a single unauthenticated HTTP/2 request to any route that uses trailers crashes the server process and drops all in-flight requests, and it can be repeated on every restart. The issue is fixed in fastify 5.12.5, and users should upgrade to 5.12.5 or later. As a workaround, avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until upgrading.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
fastify fastify From 5.12.5 (inc)
fastify fastify From 4.29.2 (inc)
fastify fastify to 5.12.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Fastify versions before 5.12.5. When a route registers a response trailer over HTTP/2, Fastify incorrectly sets the Transfer-Encoding: chunked header, which violates HTTP/2 standards. Node.js throws an uncaught exception, crashing the server and dropping all in-flight requests. An attacker can exploit this with a single unauthenticated HTTP/2 request to any route using trailers.

Detection Guidance

To detect this vulnerability, check if your Fastify server is running versions before 5.12.5 and has HTTP/2 enabled with routes using reply.trailer(). Inspect server logs for uncaught ERR_HTTP2_INVALID_CONNECTION_HEADERS exceptions after HTTP/2 requests. Use commands like 'npm list fastify' to verify the installed version.

Impact Analysis

This vulnerability can cause a Denial of Service (DoS) by crashing the server process. All in-flight requests are dropped, and the server must be restarted. It only affects applications using HTTP/2 with routes that register trailers. HTTP/1.x responses are unaffected.

Mitigation Strategies

Immediately upgrade Fastify to version 5.12.5 or later. If upgrading is not possible, disable HTTP/2 temporarily or avoid using reply.trailer() on HTTP/2 routes. Monitor server logs for crashes and ensure no unauthenticated HTTP/2 requests are reaching vulnerable routes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92081. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart