GHSA-4MH8-R7RC-XPVC
Vulnerability from github – Published: 2026-09-30 23:53 – Updated: 2026-09-30 23:53Impact
fastify crashes with an uncaught ERR_HTTP2_INVALID_CONNECTION_HEADERS exception when a route that registers a response trailer via reply.trailer() is served over HTTP/2. Fastify unconditionally adds the Transfer-Encoding: chunked header when a trailer is set, which is forbidden on HTTP/2, so Node.js throws while serializing the response headers. The exception is not caught and becomes an uncaughtException, terminating the Node.js process.
One unauthenticated HTTP/2 request to any route that uses trailers is enough to crash the server, dropping all in-flight requests, and the request can be repeated to keep the process down. Applications are affected only when HTTP/2 is enabled (http2: true) and at least one route registers a trailer. HTTP/1.x responses are not affected.
Patches
Upgrade to fastify 5.12.5 or later.
Workarounds
Avoid registering response trailers with reply.trailer() on routes served over HTTP/2 until upgrading.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "fastify"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.12.5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-92081"
],
"database_specific": {
"cwe_ids": [
"CWE-248"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-30T23:53:44Z",
"nvd_published_at": "2026-09-16T09:17:10Z",
"severity": "MODERATE"
},
"details": "### Impact\n\n`fastify` crashes with an uncaught `ERR_HTTP2_INVALID_CONNECTION_HEADERS` exception when a route that registers a response trailer via `reply.trailer()` is served over HTTP/2. Fastify unconditionally adds the `Transfer-Encoding: chunked` header when a trailer is set, which is forbidden on HTTP/2, so Node.js throws while serializing the response headers. The exception is not caught and becomes an uncaughtException, terminating the Node.js process.\n\nOne unauthenticated HTTP/2 request to any route that uses trailers is enough to crash the server, dropping all in-flight requests, and the request can be repeated to keep the process down. Applications are affected only when HTTP/2 is enabled (`http2: true`) and at least one route registers a trailer. HTTP/1.x responses are not affected.\n\n### Patches\n\nUpgrade to `fastify` `5.12.5` or later.\n\n### Workarounds\n\nAvoid registering response trailers with `reply.trailer()` on routes served over HTTP/2 until upgrading.",
"id": "GHSA-4mh8-r7rc-xpvc",
"modified": "2026-09-30T23:53:44Z",
"published": "2026-09-30T23:53:44Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/fastify/fastify/security/advisories/GHSA-4mh8-r7rc-xpvc"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92081"
},
{
"type": "WEB",
"url": "https://github.com/fastify/fastify/issues/6574"
},
{
"type": "WEB",
"url": "https://github.com/fastify/fastify/commit/ad06a4c3fe8a944a904f38068249b18b8f552e90"
},
{
"type": "WEB",
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"type": "PACKAGE",
"url": "https://github.com/fastify/fastify"
},
{
"type": "WEB",
"url": "https://github.com/fastify/fastify/releases/tag/v5.12.5"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.