Skip to content

VEX for CVE-2025-32442: In fastify different validation strategies for different content types have a possibility to bypass validation #148

@rainer-exxcellent

Description

@rainer-exxcellent

Dependabot has reported the following vulnerability: CVE-2025-32442

Csaf-validator-service is not affected by this vulnerability because :

  • only the versions v1.3.50 and v1.3.51 of the csaf-validator-service have dependencies to the affected fastify versions
  • csaf-validator-service uses only one content type (JSON) and has no validation strategies

In Version v1.3.52 the dependency to fastify is updated to a non-vulnerable version

This is shown in the following VAX:

bsi-2025-0003.json

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions