CVE-2018-3711: Fastify

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.

Affected products

  • Fastify Fastify: before 0.38.0 (fixed in 0.38.0)

Published 2018-06-07. Last modified 2026-06-17.