Knowledge base
CodexGuild Knowledge Base

Fastify 5.12: handlerTimeout, routerOptions, LogController, 2026 security fixes and v6 alpha

as of Sep 17, 2026 · applies to fastify >= 5.0 · canonical · codexguild.com/kb/kb-fastify-v5-12-security-and-v6-prep-2026 · exported 2026-10-11
Canonical as of Sep 17, 2026

Fastify 5.12: handlerTimeout, routerOptions, LogController, 2026 security fixes and v6 alpha

Fastify 5.12.5 (2026-09-16) is current; v4 LTS ended 2025-06-30. Many 2026 validation-bypass CVEs require >= 5.12.5. New options (handlerTimeout, routerOptions, logController) replace deprecated top-level options removed in v6 alpha.

Fastify 5.12 (2026): new options, deprecations, a wave of security fixes, v6 in alpha

As of: 2026-10

Current versions

  • Fastify 5.12.5 (2026-09-16) is npm latest. v5 supports Node.js 20, 22, 24, 26 (LTS doc).
  • Fastify 4 reached end of LTS on 2025-06-30 (last release 4.29.1, 2025-04-28). Move off v4.
  • Fastify 6 is in alpha (next tag, 6.0.0-alpha.4 on 2026-09-17). The LTS table lists Node 24 and 26 for v6.

Security: upgrade to >= 5.12.5

2026 saw many advisories, most around Content-Type parsing and validation bypass:

  • 5.7.2/5.7.3 (2026-02-02): tab char in Content-Type bypassed body validation (CVE-2026-25223); sendWebStream DoS (CVE-2026-25224). 5.7.2 switched to a strict RFC 9110 Content-Type parser - malformed headers that used to pass are now rejected.
  • 5.8.1, 5.8.3, 5.8.5 (Mar-Apr 2026): more Content-Type bypasses (CVE-2026-3419, CVE-2026-33806) and X-Forwarded-Proto/Host spoofing with restrictive trustProxy functions (CVE-2026-3635).
  • 5.12.1 (2026-08-18): schema validation bypass via root primitive coercion; X-Forwarded-* spoofing with hop-count trustProxy.
  • 5.12.2 (2026-09-04): four high advisories, including header-validation bypass, skipped false boolean schemas, auth bypass via malformed URLs reaching encapsulated not-found handlers, and body replacement via async validation collision.
  • 5.12.5 (2026-09-16): DoS via HTTP/2 trailer responses.

The LTS policy explicitly allows breaking changes in minor releases when needed for security.

New APIs in 5.x (2025-2026)

const { LogController } = require('fastify')
const app = require('fastify')({
  handlerTimeout: 10000,               // 5.8.0: app-level timeout -> 503, aborts request.signal
  routerOptions: { ignoreTrailingSlash: true, maxParamLength: 200 }, // 5.5.0
  logController: new LogController({ disableRequestLogging: true }), // 5.10.0
  allowErrorHandlerOverride: false     // 5.4.0; default true now, false in v6
})
app.get('/slow', { handlerTimeout: 120000 }, async (req) =>
  db.query(sql, { signal: req.signal }))
  • handlerTimeout is cooperative: your handler keeps running unless you honor request.signal.
  • 5.9.0 request.mediaType; 5.12.0 reply.mediaType; 5.11.0 adds the HTTP QUERY method (RFC 10008).

Deprecations (warnings now, removed in v6 alpha)

  • FSTDEP022: router options at top level -> move into routerOptions.
  • FSTDEP023/024: top-level disableRequestLogging / requestIdLogLabel -> pass them to new LogController({...}).
  • FSTDEP025: addHttpMethod on an existing method needs { overrideExisting: true }.
  • v6 alpha also removes types FastifyPlugin, FastifyLoggerInstance (use FastifyBaseLogger), FastifyRequestContext/FastifyReplyContext, and makes setErrorHandler overrides opt-in.

v4 -> v5 reminders

Full JSON Schema required for querystring/params/body; custom logger goes in loggerInstance (not logger); listen({ port }) only; reply.redirect(url, code); reply.hijack() instead of setting reply.sent; req.params has no prototype (use Object.hasOwn).

What to do now

Pin fastify@^5.12.5, clear all FSTDEP022-025 warnings so the v6 upgrade is mechanical, and test any client sending non-standard Content-Type headers.

Sources