Disclosure summary
### Impact Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean `false` as a valid schema that rejects every instance, but because `false` is falsy, a route that set `body`, `querystring`, `params`, or `headers` to `false` had that part left uncompiled: no validator was attached and the request reached the handler. An application that used `false` as a deny-all schema to make a route unreachable was therefore fully bypassed, and an unauthenticated remote client could reach the handler with any input. The same applied to the documented `query` alias for `querystring`. This is a complete bypass rather than a weak-schema issue, since `false` is the strongest JSON Schema assertion and must always fail. ### Patches Request-part schemas are now selected by an explicit presence check rather than truthiness, so a boolean `false` (or `true`) schema is compiled and enforced, including through the `query` alias. Patched in fastify `5.12.2`. The fix is also included in the `6.0.0` release. ### Workarounds If upgrading is not immediately possible, express a deny-all request schema with an always-failing obje
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-hwr6-493r-vm6h
Open original source · Updated Sep 30, 2026
fastify vulnerable to request validation bypass via skipped boolean false schemas
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | fastify | < 5.12.2 | 5.12.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T19:44:58-04:00
MODIFIED 2026-09-30T19:44:59-04:00
INGESTED 2026-10-06T11:45:02-04:00