CVE-2022-39386 is a denial-of-service vulnerability affecting @fastify/websocket and fastify-websocket, where a specially crafted packet can crash the application. Rated 7.5 HIGH, this network-exploitable flaw requires no user interaction and can lead to complete application unavailability. While no active exploitation or public exploit code is reported, and community discussion is minimal, patched versions 7.1.1 (Fastify v4) and 5.0.1 (Fastify v3) are available, with upgrading being the recommended mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, < 7.1.1CPE matchmatch criteria | cpe:2.3:a:fastify:websocket:*:*:*:*:*:node.js:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:fastify:websocket:5.0.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.