logo

25 Million Users at Risk: Fastify Publicly Discloses PoC Exploit for Single-Space Security Bypass

ID: d09521ff-f37c-581c-933c-53d6c8b57c75

STIX ID: report--d09521ff-f37c-581c-933c-53d6c8b57c75

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

A newly disclosed Fastify vulnerability (CVE-2026-33806, CVSS 7.5) allows an attacker to bypass request schema validation by prepending a single space to the Content-Type header (e.g., ' application/json'), causing the validator to skip checks; a public PoC and an urgent patch (upgrade to v5.8.5; add trimStart() in getEssenceMediaType) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.