{"id":"GHSA-xw5p-hw6r-2j98","summary":"Denial of service in fastify","details":"A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.","aliases":["CVE-2020-8192"],"modified":"2023-11-08T04:04:15.479565Z","published":"2020-08-05T14:53:22Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-08-03T21:25:40Z","nvd_published_at":null,"cwe_ids":["CWE-400"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8192"},{"type":"WEB","url":"https://github.com/fastify/fastify/commit/74c3157ca90c3ffed9e4434f63c2017471ec970e"},{"type":"WEB","url":"https://hackerone.com/reports/903521"}],"affected":[{"package":{"name":"fastify","ecosystem":"npm","purl":"pkg:npm/fastify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.15.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-xw5p-hw6r-2j98/GHSA-xw5p-hw6r-2j98.json"}}],"schema_version":"1.9.0"}