OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-84469: fastify vulnerable to request validation bypass via skipped boolean false schemas

GitHub Advisories · officialPublished Sep 30, 2026Risk 37/100

### Impact Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean `false` as a valid schema that rejects every instance, but because `false` is falsy, a route that set `body`, `querystring`, `params`, or `headers` to `false` had that part left uncompiled: no validator was attached and the request reached the handler. An application that used `false` as a deny-all schema to make a route unreachable was therefore fully bypassed, and an unauthenticated remote client could reach the handler with any input. The same applied to the documented `query` alias for `querystring`. This is a complete bypass rather than a weak-schema issue, since `false` is the strongest JSON Schema assertion and must always fail. ### Patches Request-part schemas are now selected by an explicit presence check rather than truthiness, so a boolean `false` (or `true`) schema is compiled and enforced, including through the `query` alias. Patched in fastify `5.12.2`. The fix is also included in the `6.0.0` release. ### Workarounds If upgrading is not immediately possible, express a deny-all request schema with an always-failing object schema instead of the boolean `false` (for example `{ "not": {} }`), or reject the request in an `onRequest` hook.

Upgrade affected packages to a patched version: fastify 5.12.2.

Vendor
Not specified
Product
fastify
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source