top of page
perceptive_background_267k.jpg

@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthentic…

Published:

3 mei 2026 om 22:00:00

Alert date:

4 mei 2026 om 21:01:39

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

CVE-2026-7768 affects @fastify/accepts-serializer versions 6.0.3 and below. The vulnerability allows remote unauthenticated attackers to cause denial of service by sending many distinct Accept header variants. This causes unbounded cache growth, eventually exhausting Node.js heap memory and crashing the process. The issue stems from cached serializer-selection results without size limits or eviction policies. Fixed in version 6.0.4 with LRU cache implementation limiting entries to 100 by default. The cacheSize plugin option allows configuration of cache limits.

Technical details

Mitigation steps:

Affected products:

@fastify/accepts-serializer
Node.js

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page