@fastify/cors is vulnerable to Insecure Default Variable Initialization
15
Low Risk
Affected versions of this package do not enforce the most secure default CORS safelist methods, potentially allowing unintended HTTP methods in cross-origin requests.
You are affected if you are using a version that falls within the vulnerable range.
@fastify/cors is vulnerable to Insecure Default Variable Initialization in versions 7.0.0 - 10.1.0.
Upgrade the @fastify/cors library to the latest patched version or ensure that the methods parameter in fastify.register(...) is configured securely. Note that this patch may introduce breaking changes.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant