Description
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.
Remediation
References
https://github.com/fastify/fastify/pull/627
https://hackerone.com/reports/303632
Related Vulnerabilities
CVE-2022-25851 Vulnerability in maven package org.webjars.npm:jpeg-js
CVE-2022-25855 Vulnerability in npm package create-choo-app3
CVE-2022-1243 Vulnerability in maven package org.webjars.npm:urijs
CVE-2022-26969 Vulnerability in npm package directus
CVE-2020-26939 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk15on