CVE-2026-84428: Schema Validation Bypass in Fastify Header Normalization
Fastify versions prior to 5.12.2 contain a header schema validation bypass (CVE-2026-84428, CVSS 7.5). Shallow normalization of header schemas fails to lowercase nested or conditional rules, so mixed-case trigger headers silently skip conditional checks, letting unauthenticated attackers bypass authorization or security headers. The flaw is fixed in Fastify 5.12.2.
- CVE-2026-84428 carries a CVSS score of 7.5 (High)
- Fastify versions below 5.12.2 are affected; fixed in 5.12.2
- Mixed-case conditional header schemas silently skip validation checks
- A proof-of-concept exists; not listed in CISA KEV
Read next
Security