Fastify Fastify/oauth2 — known CVE vulnerabilities
Every CVE whose affected-product data names Fastify Fastify/oauth2, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (1)
CVE-2026-18165 — CVSS 4.2 (medium): @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth…