Package compatibility

Fastify 0.36

What Node.js versions does this Fastify version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
>=4.5
Tip version
0.36.0
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other Fastify lines

Security

Advisories affecting Fastify 0.36 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
5
Known exploited
0
Highest CVSS
  • CVE-2026-3635GHSA-444r-cwp2-x5xf

    fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections

    Affected:
    <5.8.3
    Fixed in:
    5.8.3
    Source:
    OSV source · Advisory
  • CVE-2026-25224GHSA-mrq3-vjjr-p77c

    Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream

    Affected:
    <5.7.3
    Fixed in:
    5.7.3
    Source:
    OSV source · Advisory
  • CVE-2026-25223GHSA-jx2c-rxcm-jvmq

    Fastify's Content-Type header tab character allows body validation bypass

    Affected:
    <5.7.2
    Fixed in:
    5.7.2
    Source:
    OSV source · Advisory
  • CVE-2020-8192GHSA-xw5p-hw6r-2j98

    Denial of service in fastify

    Affected:
    <2.15.1
    Fixed in:
    2.15.1
    Source:
    OSV source · Advisory
  • CVE-2018-3711GHSA-mq6c-fh97-4gwv

    Denial of Service vulnerability with large JSON payloads in fastify

    Affected:
    <0.38.0
    Fixed in:
    0.38.0
    Source:
    OSV source · Advisory