Package compatibility
Fastify 0.36
What Node.js versions does this Fastify version support?
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Declared Node.js requirement
- engines.node
- >=4.5
- Tip version
- 0.36.0
- Source
- npm Registry (engines.node)
Node.js compatibility matrix
Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.
Other Fastify lines
Security
Advisories affecting Fastify 0.36 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 5
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2026-3635GHSA-444r-cwp2-x5xf
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
- Affected:
- <5.8.3
- Fixed in:
- 5.8.3
- Source:
- OSV source · Advisory
- CVE-2026-25224GHSA-mrq3-vjjr-p77c
Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
- Affected:
- <5.7.3
- Fixed in:
- 5.7.3
- Source:
- OSV source · Advisory
- CVE-2026-25223GHSA-jx2c-rxcm-jvmq
Fastify's Content-Type header tab character allows body validation bypass
- Affected:
- <5.7.2
- Fixed in:
- 5.7.2
- Source:
- OSV source · Advisory
- CVE-2020-8192GHSA-xw5p-hw6r-2j98
Denial of service in fastify
- Affected:
- <2.15.1
- Fixed in:
- 2.15.1
- Source:
- OSV source · Advisory
- CVE-2018-3711GHSA-mq6c-fh97-4gwv
Denial of Service vulnerability with large JSON payloads in fastify
- Affected:
- <0.38.0
- Fixed in:
- 0.38.0
- Source:
- OSV source · Advisory
