Fastify 5.12: handlerTimeout, routerOptions, LogController, 2026 security fixes and v6 alpha
Fastify 5.12: handlerTimeout, routerOptions, LogController, 2026 security fixes and v6 alpha
Fastify 5.12.5 (2026-09-16) is current; v4 LTS ended 2025-06-30. Many 2026 validation-bypass CVEs require >= 5.12.5. New options (handlerTimeout, routerOptions, logController) replace deprecated top-level options removed in v6 alpha.
Fastify 5.12 (2026): new options, deprecations, a wave of security fixes, v6 in alpha
As of: 2026-10
Current versions
- Fastify 5.12.5 (2026-09-16) is npm
latest. v5 supports Node.js 20, 22, 24, 26 (LTS doc). - Fastify 4 reached end of LTS on 2025-06-30 (last release 4.29.1, 2025-04-28). Move off v4.
- Fastify 6 is in alpha (
nexttag, 6.0.0-alpha.4 on 2026-09-17). The LTS table lists Node 24 and 26 for v6.
Security: upgrade to >= 5.12.5
2026 saw many advisories, most around Content-Type parsing and validation bypass:
- 5.7.2/5.7.3 (2026-02-02): tab char in Content-Type bypassed body validation (CVE-2026-25223);
sendWebStreamDoS (CVE-2026-25224). 5.7.2 switched to a strict RFC 9110 Content-Type parser - malformed headers that used to pass are now rejected. - 5.8.1, 5.8.3, 5.8.5 (Mar-Apr 2026): more Content-Type bypasses (CVE-2026-3419, CVE-2026-33806) and
X-Forwarded-Proto/Hostspoofing with restrictivetrustProxyfunctions (CVE-2026-3635). - 5.12.1 (2026-08-18): schema validation bypass via root primitive coercion;
X-Forwarded-*spoofing with hop-counttrustProxy. - 5.12.2 (2026-09-04): four high advisories, including header-validation bypass, skipped
falseboolean schemas, auth bypass via malformed URLs reaching encapsulated not-found handlers, and body replacement via async validation collision. - 5.12.5 (2026-09-16): DoS via HTTP/2 trailer responses.
The LTS policy explicitly allows breaking changes in minor releases when needed for security.
New APIs in 5.x (2025-2026)
const { LogController } = require('fastify')
const app = require('fastify')({
handlerTimeout: 10000, // 5.8.0: app-level timeout -> 503, aborts request.signal
routerOptions: { ignoreTrailingSlash: true, maxParamLength: 200 }, // 5.5.0
logController: new LogController({ disableRequestLogging: true }), // 5.10.0
allowErrorHandlerOverride: false // 5.4.0; default true now, false in v6
})
app.get('/slow', { handlerTimeout: 120000 }, async (req) =>
db.query(sql, { signal: req.signal }))
handlerTimeoutis cooperative: your handler keeps running unless you honorrequest.signal.- 5.9.0
request.mediaType; 5.12.0reply.mediaType; 5.11.0 adds the HTTPQUERYmethod (RFC 10008).
Deprecations (warnings now, removed in v6 alpha)
- FSTDEP022: router options at top level -> move into
routerOptions. - FSTDEP023/024: top-level
disableRequestLogging/requestIdLogLabel-> pass them tonew LogController({...}). - FSTDEP025:
addHttpMethodon an existing method needs{ overrideExisting: true }. - v6 alpha also removes types
FastifyPlugin,FastifyLoggerInstance(useFastifyBaseLogger),FastifyRequestContext/FastifyReplyContext, and makessetErrorHandleroverrides opt-in.
v4 -> v5 reminders
Full JSON Schema required for querystring/params/body; custom logger goes in loggerInstance (not logger); listen({ port }) only; reply.redirect(url, code); reply.hijack() instead of setting reply.sent; req.params has no prototype (use Object.hasOwn).
What to do now
Pin fastify@^5.12.5, clear all FSTDEP022-025 warnings so the v6 upgrade is mechanical, and test any client sending non-standard Content-Type headers.
Sources
- https://github.com/fastify/fastify/releases/tag/v5.12.5
- https://github.com/fastify/fastify/releases/tag/v5.12.2
- https://github.com/fastify/fastify/releases/tag/v5.12.0
- https://github.com/fastify/fastify/releases/tag/v5.11.0
- https://github.com/fastify/fastify/releases/tag/v5.10.0
- https://github.com/fastify/fastify/releases/tag/v5.8.0
- https://github.com/fastify/fastify/releases/tag/v5.7.2
- https://github.com/fastify/fastify/releases/tag/v6.0.0-alpha.0
- https://github.com/fastify/fastify/security/advisories
- https://github.com/fastify/fastify/blob/main/docs/Reference/LTS.md
- https://github.com/fastify/fastify/blob/main/docs/Reference/Server.md
- https://github.com/fastify/fastify/blob/main/docs/Reference/Warnings.md
- https://github.com/fastify/fastify/blob/main/docs/Guides/Migration-Guide-V5.md