HIGH
@fastify/rate-limit
CVE published 2026-07-29
CVE-2026-15144
The CVE-2026-15144 vulnerability affects the @fastify/rate-limit package, allowing IPv6 clients to bypass rate limits by rotating addresses or rewriting them. This issue impacts applications protecting sensitive endpoints like authentication or expensive API calls. The vulnerability has a CVSS score of 7.3 and is classified as HIGH severity. The NVD entry for this CVE is currently Analyzed. Developers and [truncated]