CVE-2026-25223 is a validation bypass vulnerability in Fastify, a Node.js web framework, affecting versions prior to 5.7.2. Attackers can circumvent request body validation schemas by appending a tab character and arbitrary content to the Content-Type header, allowing the server to process an unvalidated body as the original content type. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-exploitable flaw with low attack complexity and high impact on integrity, but no impact on confidentiality or availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.7.2CPE matchmatch criteria | cpe:2.3:a:fastify:fastify:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.