{"id":"GHSA-9q9j-q6p8-xq58","summary":"fastify vulnerable to header validation bypass via incomplete schema case normalization","details":"### Impact\n\nFastify lowercases header-schema property names before compiling the schema, because Node.js stores request header names in lowercase. That normalization was incomplete: it lowercased only top-level `properties` keys and the root `required` array, and did not lowercase the JSON Schema Draft 7 `dependencies` keyword (its trigger keys and dependent property names) or names in nested subschemas. As a result, a header schema that uses `dependencies` to require one header when another is present (for example `X-Admin` requiring `X-Admin-Token`) never matches the lowercased request headers, so the dependency assertion is silently skipped. An unauthenticated remote client can send the header that activates a privileged path while omitting the header the dependency was meant to require, bypassing a schema-enforced security control. The header schema is idiomatic, valid JSON Schema Draft 7, and no custom validator, malformed request, or misconfiguration is required.\n\n### Patches\n\nHeader-schema names are now normalized across all schema positions (`properties`, `required`, `dependencies`, `dependentRequired`, `dependentSchemas`, and nested subschemas). Patched in fastify `5.12.2`. The fix is also included in the `6.0.0` release. Header schemas referenced through an external shared `$ref` (registered with `addSchema`) are not reached by this normalization and now emit an `FSTSEC002` startup warning; inline the header schema to keep case-insensitive assertions in effect.\n\n### Workarounds\n\nIf upgrading is not immediately possible, write header-schema names in lowercase so the `dependencies` and other case-sensitive assertions match Node's lowercased request headers, or enforce the cross-header requirement in an `onRequest` or `preValidation` hook instead of the schema.","aliases":["CVE-2026-84428"],"modified":"2026-10-01T00:00:05.759936763Z","published":"2026-09-30T23:44:27Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-30T23:44:27Z","nvd_published_at":"2026-09-04T11:17:19Z","cwe_ids":["CWE-178"]},"references":[{"type":"WEB","url":"https://github.com/fastify/fastify/security/advisories/GHSA-9q9j-q6p8-xq58"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84428"},{"type":"WEB","url":"https://github.com/fastify/fastify/commit/179619c8e99d54924309b9933402151ef9af37e0"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/fastify/fastify"},{"type":"WEB","url":"https://github.com/fastify/fastify/releases/tag/v5.12.2"}],"affected":[{"package":{"name":"fastify","ecosystem":"npm","purl":"pkg:npm/fastify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.12.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9q9j-q6p8-xq58/GHSA-9q9j-q6p8-xq58.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}