CVE-2026-25224

LOW

fastify < 5.7.3 - Denial of Service via Web Streams Response Handling

Title source: llm
STIX 2.1

Description

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applications that return a ReadableStream (or Response with a Web Stream body) via reply.send() are impacted. A slow or non-reading client can trigger unbounded buffering when backpressure is ignored, leading to process crashes or severe degradation. This issue has been patched in version 5.7.3.

Scores

CVSS v3 3.7
EPSS 0.0049
EPSS Percentile 38.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (2)
fastify/fastify < 5.7.3
npm/fastify 0 - 5.7.3npm
Published Feb 03, 2026
Tracked Since Feb 18, 2026