What is CVE-2026-15144?
CVE-2026-15144 is a vulnerability in @fastify/rate-limit before version 11.2.0, where rate-limit buckets are keyed by the verbatim client IP string. Due to the large address range of IPv6 and its multiple textual representations, a single client can easily bypass rate limits. Upgrading to at least version 11.2.0 is recommended.
Azərbaycanca: CVE-2026-15144 @fastify/rate-limit 11.2.0-dən əvvəlki versiyalarda IP əsaslı rate-limiting mexanizmində zəiflikdir. IPv6 ünvanlarının geniş diapazonu və müxtəlif mətn təsvirləri səbəbindən eyni müştəri limitləri asanlıqla keçə bilər. Ən azı 11.2.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of @fastify/rate-limit are affected by CVE-2026-15144?
This vulnerability affects versions of @fastify/rate-limit before 11.2.0.
How can an attacker bypass rate limits using the CVE-2026-15144 vulnerability?
Due to the large address range of IPv6 and its multiple textual representations, a single client can easily bypass the limits by altering the key for the IP-based rate-limit bucket.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.