AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-84469.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

### Impact Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean `false` as a valid schema that rejects every instance, but because `false` is falsy, a route that set `body`, `querystring`, `params`, or `headers` to `false` had that part left uncompiled: no validator was attached and the request reached the handler. An application that used `false` as a deny-all schema to make a route unreachable was therefore fully bypassed, and an unauthenticated remote client could reach the handler with any input. The same applied to the documented `query` alias for `querystring`. This is a complete bypass rather than a weak-schema issue, since `false` is the strongest JSON Schema assertion and must always fail. ### Patches Request-part schemas are now selected by an explicit presence check rather than truthiness, so a boolean `false` (or `true`) schema is compiled and enforced, including through the `query` alias. Patched in fastify `5.12.2`. The fix is also included in the `6.0.0` release. ### Workarounds If upgrading is not immediately possible, express a deny-all request schema with an always-failing obje

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-hwr6-493r-vm6h

Open original source · Updated Sep 30, 2026

fastify vulnerable to request validation bypass via skipped boolean false schemas

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
npmfastify< 5.12.25.12.2

Original records & references

PUBLISHED 2026-09-30T19:44:58-04:00
MODIFIED 2026-09-30T19:44:59-04:00
INGESTED 2026-10-06T11:45:02-04:00