CVE-2020-8192

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
30/07/2020
Last modified:
06/08/2020

Description

A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fastify:fastify:2.14.1:*:*:*:*:node.js:*:*
cpe:2.3:a:fastify:fastify:3.0.0:rc4:*:*:*:node.js:*:*


References to Advisories, Solutions, and Tools