CVE-2026-33806
Impact:
Fastify applications using schema.body.content for per-content-type body validation can have validation bypasse
Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.3.2 by the fix for CVE-2025-32442 Patches: Upgrade to fastify v5.8.5 or later.
Workarounds: None. Upgrade to the patched version.
HIGH · CVSS 7.5
EPSS 0.00107
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0