Matteo Collina
28 exploits
Active since Dec 2017
@fastify/bearer-auth <7.0.2-8.0.1 - Info Disclosure
CVSS 7.5
undici < 5.28.4 - Improper Authorization via Uncleared Headers in undici.request()
CVSS 3.9
Undici < 5.28.4 - Improper Access Control via Integrity Option Tampering
CVSS 2.6
Undici <5.28.5,6.21.1,7.2.3 - Info Disclosure
CVSS 6.8
Undici <5.28.5,6.21.1,7.2.3 - Info Disclosure
CVSS 6.8
mercurius < 16.8.0 - Incorrect Authorization via WebSocket Subscription Query Depth Bypass
CVSS 8.2
MQTT.js 2.x.x < 2.15.0 - Denial of Service via PUBLISH Ticket Handling
CVSS 6.5
aedes < 0.35.0 - Improper Authorization
CVSS 5.3
fastify-reply-from < 4.0.2 - URL Prefix Bypass via Crafted Request
CVSS 10.0
fastify-http-proxy < 4.3.1 - URL Prefix Bypass via Crafted Request
CVSS 10.0
msgpack5 < 3.6.1 - Prototype Poisoning via __proto__ Key Decoding
CVSS 6.7
fastify-multipart < 5.3.1 - Denial of Service via Constructor Property Bypass
CVSS 7.5
@fastify/bearer-auth <7.0.2-8.0.1 - Info Disclosure
CVSS 7.5
Undici < 5.19.1 - Regular Expression Denial of Service via Header Value Normalization
CVSS 7.5
fastify/passport < 1.1.0 - Cross-Site Request Forgery Protection Bypass via Session Fixation
CVSS 6.5
Fastify Swagger-UI - Information Disclosure
CVSS 5.3
Undici 6.0.0-6.6.0 - Use-After-Free via Unconsumed Fetch Body
CVSS 6.5
Undici < 5.28.3 - Exposure of Sensitive Information via Proxy-Authentication Header
CVSS 3.9
undici < 5.28.4 - Improper Authorization via Uncleared Headers in undici.request()
CVSS 3.9
Undici < 5.28.4 - Improper Access Control via Integrity Option Tampering
CVSS 2.6
@festify/secure-session - Info Disclosure
CVSS 7.4
Undici <5.28.5,6.21.1,7.2.3 - Info Disclosure
CVSS 6.8
fastify 5.0.0-5.3.0 and 4.29.0 - Content-Type Validation Bypass via Altered Whitespace or Casing
CVSS 7.5
Undici < 5.29.0, 6.0.0-6.21.1, 7.0.0-7.4.9 - Memory Leak via Repeated Webhook Calls
CVSS 3.1
fastify/reply-from < 12.5.0 - Unintended Proxy Access via Malicious URL
CVSS 5.4