Fastify Fastify/rate-limit — known CVE vulnerabilities
Every CVE whose affected-product data names Fastify Fastify/rate-limit, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (1)
CVE-2026-15144 — CVSS 7.3 (high): @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6…