A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| fastify(npm) | 0 | 2.15.1 | N/A |
CVSS Metrics