Uncaught Exception in Fastify - CVE-2026-92081
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an uncaught exception in Fastify's HTTP/2 response trailer handling when serializing a response with a registered trailer. A remote attacker can send an HTTP/2 request to a route that registers a response trailer to cause a denial of service.
Applications are affected only when HTTP/2 is enabled and at least one route registers a trailer; HTTP/1.x responses are not affected.