CVE-2026-3419

MEDIUM
中文标题:
(暂无数据)
英文标题:
Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after th
CVSS分数: 5.3
发布时间: 2026-03-06 18:16:22
漏洞类型: (暂无数据)
状态: PUBLISHED
数据质量分数: 0.40
数据版本: v1
漏洞描述
中文描述:

(暂无数据)

英文描述:

Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in violation of RFC 9110 §8.3.1(https://httpwg.org/specs/rfc9110.html#field.content-type). For example, a request sent with Content-Type: application/json garbage passes validation and is processed normally, rather than being rejected with 415 Unsupported Media Type. When regex-based content-type parsers are in use (a documented Fastify feature), the malformed value is matched against registered parsers using the full string including the trailing garbage. This means a request with an invalid content-type may be routed to and processed by a parser it should never have reached. Impact: An attacker can send requests with RFC-invalid Content-Type headers that bypass validity checks, reach content-type parser matching, and be processed by the server. Requests that should be rejected at the validation stage are instead handled as if the content-type were valid. Workarounds: Deploy a WAF rule to protect against this Fix: The fix is available starting with v5.8.1.

CWE类型:
CWE-185
标签:
(暂无数据)
受影响产品
暂无受影响产品信息
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
ce714d77-add3-4f53-aff5-83d477b104bb OTHER
nvd.nist.gov
访问
ce714d77-add3-4f53-aff5-83d477b104bb OTHER
nvd.nist.gov
访问
ce714d77-add3-4f53-aff5-83d477b104bb OTHER
nvd.nist.gov
访问
ce714d77-add3-4f53-aff5-83d477b104bb OTHER
nvd.nist.gov
访问
ce714d77-add3-4f53-aff5-83d477b104bb OTHER
nvd.nist.gov
访问
ce714d77-add3-4f53-aff5-83d477b104bb OTHER
nvd.nist.gov
访问
CVSS评分详情
5.3
MEDIUM
CVSS向量: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS版本: 3.1
机密性
NONE
完整性
LOW
可用性
NONE
时间信息
发布时间:
2026-03-06 18:16:22
修改时间:
2026-03-06 18:16:22
创建时间:
2026-03-07 06:00:02
更新时间:
2026-03-10 06:00:03
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
NVD nvd_CVE-2026-3419 2026-03-07 02:00:04 2026-03-06 22:00:02
版本与语言
当前版本: v1
主要语言: EN
支持语言:
EN
安全公告
暂无安全公告信息
变更历史
暂无变更历史