Fastify Program Statistics
5 total issues disclosed
$0 total paid publicly
Most disclosed (2 disclosures) — None supplied
Disclosed Reports
| Report Title | Vulnerability Type | Disclosed By | Severity | Disclosed on |
|---|---|---|---|---|
| DoS via Unbounded Memory Allocation in sendWebStream on Fastify v5.7.0+ leads to OOM crash when backpressure is ignored | None supplied | onlybugs05 | No rating | 2026-03-05 |
| Remote Code Execution via unsafe usage of `reply.view({ raw })` in @fastify/view (EJS template engine) | None supplied | oblivionsage | None | 2025-05-28 |
| Deny of service via malicious Content-Type | Uncontrolled Resource Consumption | bitk | High | 2022-10-10 |
| 1-click DOS in fastify-static via directly passing user's input to new URL() of NodeJS without try/catch | Uncontrolled Resource Consumption | drstrnegth | Medium | 2021-10-11 |
| Open redirect in fastify-static via mishandled user's input when attempt to redirect | Open Redirect | drstrnegth | Low | 2021-10-11 |
Getting started
Learn about vulnerability types
Getting started in bug bounties
Test your knowledge
Free Web Application Challenges
Guides for your hunts
ZSeano's Methodology
Effective Note Taking for bug bounties
Useful Resources
Disclosed HackerOne Reports
Our community
Endorsed Members
Hackevents
Member Articles