脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2026-15144 |
|
fastify の脆弱性 (CVE-2026-15144)
fastify に 脆弱性 (CVE-2026-15144) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-18174 |
|
fastify の脆弱性 (CVE-2026-18174)
fastify に 脆弱性 (CVE-2026-18174) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7120 |
|
@fastify/static の脆弱性 (CVE-2026-7120)
@fastify/static に 脆弱性 (CVE-2026-7120) が存在。不正な操作・情報露出のリスクがあります。``allowedPath`` 経由で攻撃可能。対策: `10.1.2` 以上に更新。
|
| CVE-2026-15074 |
|
@fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to route guard bypass via path traversal
|
| CVE-2026-16117 |
|
fastify の脆弱性 (CVE-2026-16117)
fastify に 脆弱性 (CVE-2026-16117) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-16158 |
|
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destinat...
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs....
|
| CVE-2026-15631 |
|
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
|
| CVE-2026-14198 |
|
fastify の脆弱性 (CVE-2026-14198)
fastify に 脆弱性 (CVE-2026-14198) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-14181 |
|
dos の脆弱性 (CVE-2026-14181)
dos に 脆弱性 (CVE-2026-14181) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-6556 |
|
express の脆弱性 (CVE-2026-6556)
express に 脆弱性 (CVE-2026-6556) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-7768 |
|
@fastify/accepts-serializer の脆弱性 (CVE-2026-7768)
@fastify/accepts-serializer に 脆弱性 (CVE-2026-7768) が存在。不正な操作・情報露出のリスクがあります。``Accept`` 経由で攻撃可能。対策: `6.0.4` 以上に更新。
|
| CVE-2026-33804 |
|
fastify の脆弱性 (CVE-2026-33804)
fastify に 脆弱性 (CVE-2026-33804) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-6270 |
|
fastify の脆弱性 (CVE-2026-6270)
fastify に 脆弱性 (CVE-2026-6270) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-33805 |
|
@fastify/reply-from の脆弱性 (CVE-2026-33805)
@fastify/reply-from に 脆弱性 (CVE-2026-33805) が存在。データの不正な改ざんを許す可能性があります。``Connection`` 経由で攻撃可能。対策: `12.6.2` 以上に更新。
|
| CVE-2026-33808 |
|
@fastify/express の脆弱性 (CVE-2026-33808)
@fastify/express に 脆弱性 (CVE-2026-33808) が存在。機密情報が外部に流出する可能性があります。`GET //admin/dashboard` 経由で攻撃可能。対策: `4.0.3` 以上に更新。
|
| CVE-2026-33807 |
|
express の脆弱性 (CVE-2026-33807)
express に 脆弱性 (CVE-2026-33807) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-33806 |
|
fastify の脆弱性 (CVE-2026-33806)
fastify に 脆弱性 (CVE-2026-33806) が存在。データの不正な改ざんを許す可能性があります。
|
| CVE-2026-2880 |
|
fastify の脆弱性 (CVE-2026-2880)
fastify に 脆弱性 (CVE-2026-2880) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-25223 |
|
fastify の脆弱性 (CVE-2026-25223)
fastify に 脆弱性 (CVE-2026-25223) が存在。データの不正な改ざんを許す可能性があります。
|
| CVE-2026-22031 |
|
fastify の脆弱性 (CVE-2026-22031)
fastify に 脆弱性 (CVE-2026-22031) が存在。機密情報が外部に流出する可能性があります。
|