Disclosure summary
### Impact Fastify lowercases header-schema property names before compiling the schema, because Node.js stores request header names in lowercase. That normalization was incomplete: it lowercased only top-level `properties` keys and the root `required` array, and did not lowercase the JSON Schema Draft 7 `dependencies` keyword (its trigger keys and dependent property names) or names in nested subschemas. As a result, a header schema that uses `dependencies` to require one header when another is present (for example `X-Admin` requiring `X-Admin-Token`) never matches the lowercased request headers, so the dependency assertion is silently skipped. An unauthenticated remote client can send the header that activates a privileged path while omitting the header the dependency was meant to require, bypassing a schema-enforced security control. The header schema is idiomatic, valid JSON Schema Draft 7, and no custom validator, malformed request, or misconfiguration is required. ### Patches Header-schema names are now normalized across all schema positions (`properties`, `required`, `dependencies`, `dependentRequired`, `dependentSchemas`, and nested subschemas). Patched in fastify `5.12.2`. T
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-9q9j-q6p8-xq58
Open original source · Updated Sep 30, 2026
fastify vulnerable to header validation bypass via incomplete schema case normalization
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | fastify | < 5.12.2 | 5.12.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T19:44:27-04:00
MODIFIED 2026-09-30T19:44:29-04:00
INGESTED 2026-10-06T11:45:02-04:00