{"id":"CVE-2025-32442","summary":"Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass","details":"Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, applications that specify different validation strategies for different content types have a possibility to bypass validation by providing a _slightly altered_ content type such as with different casing or altered whitespacing before `;`. This was patched in v5.3.1, but the initial patch did not cover all problems. This has been fully patched in v5.3.2 and v4.29.1. A workaround involves not specifying individual content types in the schema.","aliases":["CVE-2026-33806","GHSA-247c-9743-5963","GHSA-mg2h-6x62-wpwc"],"modified":"2026-08-12T03:51:40.885981181Z","published":"2025-04-18T15:59:06.670Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-1287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32442.json"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/3087928"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32442.json"},{"type":"ADVISORY","url":"https://github.com/fastify/fastify/security/advisories/GHSA-mg2h-6x62-wpwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32442"},{"type":"FIX","url":"https://github.com/fastify/fastify/commit/436da4c06dfbbb8c24adee3a64de0c51e4f47418"},{"type":"FIX","url":"https://github.com/fastify/fastify/commit/f3d2bcb3963cd570a582e5d39aab01a9ae692fe4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fastify/fastify","events":[{"introduced":"6bde7d7b0a51010d56df901cab9be5d9351b0d91"},{"fixed":"32f7e1eb97b638bad3ff8b80948e5b2c07d1b8b5"},{"introduced":"3a6d4aeb241706fc9b71858281800a0cf193a308"},{"fixed":"436da4c06dfbbb8c24adee3a64de0c51e4f47418"},{"fixed":"f3d2bcb3963cd570a582e5d39aab01a9ae692fe4"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:fastify:fastify:*:*:*:*:*:node.js:*:*","cpe:2.3:a:fastify:fastify:4.29.0:*:*:*:*:node.js:*:*"],"extracted_events":[{"introduced":"5.0.0"},{"fixed":"5.3.2"},{"introduced":"4.29.0"},{"last_affected":"4.29.0"}]}}],"versions":["4.29.0","= 4.29.0","v5.3.1","v5.3.0","v5.2.2","v5.2.1","v5.2.0","v5.1.0","v5.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32442.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}