NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3179 most downloaded on npm
Fast and low overhead web framework, for Node.js
Last release 18 days ago
16 Sep 2026
Release timing varies
gaps range from 8 days to 2 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
67 versions withdrawn
withdrawn after publishing
10 years old
331 releases · first in 2016
Nothing published for this version
docs(ecosystem): remove deprecated http-wizard and rename fastify-better-sqlite3 by @ilteoood in #6972
Full Changelog: v6.0.0-alpha.2...v6.0.0-alpha.3
One column per quarter.
docs: remove deprecated-API notices ahead of v6 cleanup by @Tony133 in #6951
Full Changelog: v6.0.0-alpha.1...v6.0.0-alpha.2
fix: remove raw response headers by @Ram-blip in #6860
Reply.prototype.mediaType by @LiviaMedeiros in #6932undefined for invalid media types by @jean-michelet in #6942Full Changelog: v6.0.0-alpha.0...v6.0.0-alpha.1
refactor(types)!: remove deprecated FastifyPlugin type by @Tony133 in #6897
Full Changelog: v5.11.3...v6.0.0-alpha.0
[Backport 5.x] perf: reduce content-type parser overhead by @github-actions[bot] in #7019
Full Changelog: v5.12.4...v5.12.5
Fixed the fastify.js version mismatch.
Fixed the fastify.js version mismatch.
Full Changelog: v5.12.2...v5.12.4
Nothing published for this version
[Backport 5.x] fix: callNotFound should run not-found preHandler regardless of registration order by @github-actions[bot] in #6973
Full Changelog: v5.12.1...v5.12.2
[Backport 5.x] test: fix reply.mediaType by @github-actions[bot] in #6950
Full Changelog: v5.12.0...v5.12.1
chore(sponsor): add testmu ai by @Eomm in #6922
Reply.prototype.mediaType by @github-actions[bot] in #6946undefined for invalid media types by @github-actions[bot] in #6947Full Changelog: v5.11.3...v5.12.0
fix: clear trailer state when removing all trailers by @Ram-blip in #6845
Full Changelog: v5.11.2...v5.11.3
fix fastify version in fastify.js
fix: add http method override warning by @jean-michelet in #6879
Full Changelog: v5.11.0...v5.11.1
chore: Bump markdownlint-cli2 from 0.22.1 to 0.23.0 by @dependabot [bot] in #6839
Content-Type parameter values by @aquie00t in #6865Full Changelog: v5.10.0...v5.11.0
docs(type-providers): clarify as const usage by @smith558 in #6772
json and charset in reply.send by @climba03003 in #6830Full Changelog: v5.9.0...v5.10.0
docs: remove deprecated leveldb plugin and update ecosystem by @Tony133 in https://github.com/fastify/fastify/pull/6661
find with some in hasKey for correct boolean semantics by @aquie00t in https://github.com/fastify/fastify/pull/6759AssertionError with FST_ERR_PLUGIN_DEPENDENCY_NOT_REGISTERED in checkDependencies by @aquie00t in https://github.com/fastify/fastify/pull/6774Full Changelog: https://github.com/fastify/fastify/compare/v5.8.5...v5.9.0
This fixes CVE CVE-2026-33806 https://github.com/fastify/fastify/security/advisories/GHSA-247c-9743-5963.
This fixes CVE CVE-2026-33806 https://github.com/fastify/fastify/security/advisories/GHSA-247c-9743-5963.
Full Changelog: https://github.com/fastify/fastify/compare/v5.8.4...v5.8.5
Full Changelog: https://github.com/fastify/fastify/compare/v5.8.3...v5.8.4
Full Changelog: https://github.com/fastify/fastify/compare/v5.8.3...v5.8.4
This fixes CVE CVE-2026-3635 https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf.
This fixes CVE CVE-2026-3635 https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf.
Full Changelog: https://github.com/fastify/fastify/compare/v5.8.2...v5.8.3
docs(ecosystem): add @yeliex/fastify-problem-details by @yeliex in https://github.com/fastify/fastify/pull/6546
Full Changelog: https://github.com/fastify/fastify/compare/v5.8.1...v5.8.2
Fixes "Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation": https://github.com/fastify/fastify/security/advisori
Fixes "Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation": https://github.com/fastify/fastify/security/advisories/GHSA-573f-x89g-hqp9.
CVE-2026-3419
Full Changelog: https://github.com/fastify/fastify/compare/v5.8.0...v5.8.1
docs(request): add host security warning references by @mcollina in https://github.com/fastify/fastify/pull/6476
tsconfig.eslint.json by @mrazauskas in https://github.com/fastify/fastify/pull/6524Full Changelog: https://github.com/fastify/fastify/compare/v5.7.4...v5.8.0
Full Changelog: https://github.com/fastify/fastify/compare/v5.7.3...v5.7.4
Full Changelog: https://github.com/fastify/fastify/compare/v5.7.3...v5.7.4
Fix https://github.com/fastify/fastify/security/advisories/GHSA-mrq3-vjjr-p77c CVE-2026-25224.
CVE-2026-25224.Full Changelog: https://github.com/fastify/fastify/compare/v5.7.2...v5.7.3
Parsing of the content-type header has been improved to a strict parser in PR #6414. This means only header values in the form described in RFC 9110 a
Parsing of the content-type header has been improved to a strict parser in PR #6414. This means only header values in the form described in RFC 9110 are accepted.
Full Changelog: https://github.com/fastify/fastify/compare/v5.7.1...v5.7.2
chore: Bump actions/checkout from 5 to 6 by @dependabot[bot] in https://github.com/fastify/fastify/pull/6434
Full Changelog: https://github.com/fastify/fastify/compare/v5.7.0...v5.7.1
docs: add non-vulnerability examples to threat model by @RafaelGSS in https://github.com/fastify/fastify/pull/6431
Full Changelog: https://github.com/fastify/fastify/compare/v5.6.2...v5.7.0
refactor: rename source file names with kebab-case by @jean-michelet in https://github.com/fastify/fastify/pull/6331
@fastify/sse as fastify core plugin to documentation and citgm by @manshusainishab in https://github.com/fastify/fastify/pull/6364nb usage by @Fdawgs in https://github.com/fastify/fastify/pull/6365Full Changelog: https://github.com/fastify/fastify/compare/v5.6.1...v5.6.2
fix: fix typo of deprecation warning FSTDEP022 by @Uzlopak in https://github.com/fastify/fastify/pull/6313
Full Changelog: https://github.com/fastify/fastify/compare/v5.6.0...v5.6.1
fix: update typescript pino type to pick by @dancastillo in https://github.com/fastify/fastify/pull/6287
Full Changelog: https://github.com/fastify/fastify/compare/v5.5.0...v5.6.0
docs: fix markdown linting issue by @Uzlopak in https://github.com/fastify/fastify/pull/6175
Full Changelog: https://github.com/fastify/fastify/compare/v5.4.0...v5.5.0
test: mv routes-* from tap by @jean-michelet in https://github.com/fastify/fastify/pull/6092
Full Changelog: https://github.com/fastify/fastify/compare/v5.3.3...v5.4.0
docs: update Vercel section by @leerob in https://github.com/fastify/fastify/pull/6046
setErrorHandler overriding a previously defined error handler on an encapsulated context by @jean-michelet in https://github.com/fastify/fastify/pull/6097fastify-diagnostics-channel by @inyourtime in https://github.com/fastify/fastify/pull/6117Full Changelog: https://github.com/fastify/fastify/compare/v5.3.2...v5.3.3
Unfortunately, v5.3.1 did not include a complete fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442. This is a…
Unfortunately, v5.3.1 did not include a complete fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442. This is a follow-up patch to cover an edge case.
Full Changelog: https://github.com/fastify/fastify/compare/v5.3.1...v5.3.2
Fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442
Full Changelog: https://github.com/fastify/fastify/compare/v5.3.0...v5.3.1
fix: wrong reply return type by @dangkyokhoang in https://github.com/fastify/fastify/pull/6026
[kState].readyPromise for garbage collection by @LiviaMedeiros in https://github.com/fastify/fastify/pull/6030Full Changelog: https://github.com/fastify/fastify/compare/v5.2.2...v5.3.0
build: use static path instead of __filename by @climba03003 in https://github.com/fastify/fastify/pull/5922
done function by @gurgunday in https://github.com/fastify/fastify/pull/5937@fastify/otel to core list by @Fdawgs in https://github.com/fastify/fastify/pull/59670.0.0.0 by @jonasongg in https://github.com/fastify/fastify/pull/5988Full Changelog: https://github.com/fastify/fastify/compare/v5.2.1...v5.2.2
chore: org members reorder by @Eomm in https://github.com/fastify/fastify/pull/5898
proxy-addr with @fastify/proxy-addr by @Fdawgs in https://github.com/fastify/fastify/pull/5913Full Changelog: https://github.com/fastify/fastify/compare/v5.2.0...v5.2.1
docs: add HeroDevs mentions to README and LTS docs by @AndreAngelantoni in https://github.com/fastify/fastify/pull/5730
fastify-mongo-sanitize and remix-fastify to comm. by @ExorTek in https://github.com/fastify/fastify/pull/5822node: prefix to bypass require.cache call for builtins by @Fdawgs in https://github.com/fastify/fastify/pull/5894node: prefix for builtins by @Fdawgs in https://github.com/fastify/fastify/pull/5896Full Changelog: https://github.com/fastify/fastify/compare/v5.1.0...v5.2.0
chore: Update Migration-Guide-V5.md by @jsumners in https://github.com/fastify/fastify/pull/5688
.exec() with .test() by @Fdawgs in https://github.com/fastify/fastify/pull/5750Full Changelog: https://github.com/fastify/fastify/compare/v5.0.0...v5.1.0
Remove deprecated variadic listen by @jsumners in https://github.com/fastify/fastify/pull/4900
decorate('name', null) in the types by @voxpelli in https://github.com/fastify/fastify/pull/4878config type in RouteShorthandOptions by @BrianValente in https://github.com/fastify/fastify/pull/5355reply.redirect() signature by @gurgunday in https://github.com/fastify/fastify/pull/5483reply.getReponseTime() in https://github.com/fastify/fastify/pull/5490http2 directive in nginx config by @LiviaMedeiros in https://github.com/fastify/fastify/pull/5548crudify-mongo plugin to community list by @aaroncadillac in https://github.com/fastify/fastify/pull/5581FSTDEP008 and FSTDEP009 by @climba03003 in https://github.com/fastify/fastify/pull/5609FSTDEP010 by @climba03003 in https://github.com/fastify/fastify/pull/5611FSTDEP021 by @gurgunday in https://github.com/fastify/fastify/pull/5613Object.hasOwn by @gurgunday in https://github.com/fastify/fastify/pull/5614FSTDEP012, FSTDEP015, FSTDEP016, FSTDEP017, FSTDEP018, FSTDEP019 by @climba03003 in https://github.com/fastify/fastify/pull/5616FSTDEP013 by @climba03003 in https://github.com/fastify/fastify/pull/5618Response replies by @barbieri in https://github.com/fastify/fastify/pull/5612neostandard setup by @voxpelli in https://github.com/fastify/fastify/pull/5635this to instance in onclose by @gurgunday in https://github.com/fastify/fastify/pull/5670Full Changelog: https://github.com/fastify/fastify/compare/v4.27.0...v5.0.0
Nothing published for this version
chore: remove deprecation 005 by @jsumners in https://github.com/fastify/fastify/pull/5589
http2 directive in nginx config by @LiviaMedeiros in https://github.com/fastify/fastify/pull/5548crudify-mongo plugin to community list by @aaroncadillac in https://github.com/fastify/fastify/pull/5581FSTDEP008 and FSTDEP009 by @climba03003 in https://github.com/fastify/fastify/pull/5609FSTDEP010 by @climba03003 in https://github.com/fastify/fastify/pull/5611FSTDEP021 by @gurgunday in https://github.com/fastify/fastify/pull/5613Object.hasOwn by @gurgunday in https://github.com/fastify/fastify/pull/5614FSTDEP012, FSTDEP015, FSTDEP016, FSTDEP017, FSTDEP018, FSTDEP019 by @climba03003 in https://github.com/fastify/fastify/pull/5616FSTDEP013 by @climba03003 in https://github.com/fastify/fastify/pull/5618Response replies by @barbieri in https://github.com/fastify/fastify/pull/5612neostandard setup by @voxpelli in https://github.com/fastify/fastify/pull/5635Full Changelog: https://github.com/fastify/fastify/compare/v5.0.0-alpha.2...v5.0.0-alpha.4
Nothing published for this version
chore: test deprecation cleanup by @Cangit in https://github.com/fastify/fastify/pull/5510
config type in RouteShorthandOptions by @BrianValente in https://github.com/fastify/fastify/pull/5355reply.redirect() signature by @gurgunday in https://github.com/fastify/fastify/pull/5483reply.getReponseTime() in https://github.com/fastify/fastify/pull/5490Full Changelog: https://github.com/fastify/fastify/compare/v5.0.0-alpha.1...v5.0.0-alpha.2
Fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442.
Fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442.
Full Changelog: https://github.com/fastify/fastify/compare/v4.29.0...v4.29.1
refactor(4.x): add deprecate warning of json shorthand by @climba03003 in https://github.com/fastify/fastify/pull/5587
config type in RouteShorthandOptions by @bastienmenis in https://github.com/fastify/fastify/pull/5527Response replies by @github-actions in https://github.com/fastify/fastify/pull/5629this to instance in onclose by @github-actions in https://github.com/fastify/fastify/pull/5679Full Changelog: https://github.com/fastify/fastify/compare/v4.28.1...v4.29.0
[Backport 4.x] fix: server.listen listener is not cleanup properly by @github-actions in https://github.com/fastify/fastify/pull/5523
Full Changelog: https://github.com/fastify/fastify/compare/v4.28.0...v4.28.1
test: fix closing - pipelining by @climba03003 in https://github.com/fastify/fastify/pull/5486
reply.redirect() signature (#5483) by @gurgunday in https://github.com/fastify/fastify/pull/5484Full Changelog: https://github.com/fastify/fastify/compare/v4.27.0...v4.28.0
docs(request): update request page by @Tony133 in https://github.com/fastify/fastify/pull/5343
remove-label job uses the wrong repo by @gurgunday in https://github.com/fastify/fastify/pull/5415reply.getSerializationFunction can return undefined by @remidewitte in https://github.com/fastify/fastify/pull/5384aborted property by @Fdawgs in https://github.com/fastify/fastify/pull/5438Full Changelog: https://github.com/fastify/fastify/compare/v4.26.2...v4.27.0
fix: typo in module exports by @lirantal in https://github.com/fastify/fastify/pull/5316
Full Changelog: https://github.com/fastify/fastify/compare/v4.26.1...v4.26.2
docs: fix misattributed property parent in deprecation warning: request.elapsedTime by @mscottnelson in https://github.com/fastify/fastify/pull/5299
Full Changelog: https://github.com/fastify/fastify/compare/v4.26.0...v4.26.1
refactor: deprecate Reply#getResponseTime() in favour of Reply#elapsedTime by @codershiba in https://github.com/fastify/fastify/pull/5263
fastify.setErrorHandler() by @codershiba in https://github.com/fastify/fastify/pull/5265Reply#getResponseTime() in favour of Reply#elapsedTime by @codershiba in https://github.com/fastify/fastify/pull/5263www. from fastify.dev urls by @Fdawgs in https://github.com/fastify/fastify/pull/5270onListen hooks are called when they should be by @bienzaaron in https://github.com/fastify/fastify/pull/5273setErrorHandler() by @codershiba in https://github.com/fastify/fastify/pull/5269.github files by @Fdawgs in https://github.com/fastify/fastify/pull/5268Full Changelog: https://github.com/fastify/fastify/compare/v4.25.2...v4.26.0
fix: npm run test:watch by @domdomegg in https://github.com/fastify/fastify/pull/5221
npm run test:watch by @domdomegg in https://github.com/fastify/fastify/pull/5221Full Changelog: https://github.com/fastify/fastify/compare/v4.25.1...v4.25.2
fix: route constraints by @climba03003 in https://github.com/fastify/fastify/pull/5207
Full Changelog: https://github.com/fastify/fastify/compare/v4.25.0...v4.25.1
refactor: migrate deprecation warnings to actual deprecation warnings by @jsumners in https://github.com/fastify/fastify/pull/5126
typeof undefined check by @Fdawgs in https://github.com/fastify/fastify/pull/5127.io domain with .dev by @Fdawgs in https://github.com/fastify/fastify/pull/5129RouteShorthandOptions without breaking request and reply types by @bienzaaron in https://github.com/fastify/fastify/pull/5147after and ready method by @nokazn in https://github.com/fastify/fastify/pull/5191Full Changelog: https://github.com/fastify/fastify/compare/v4.24.3...v4.25.0
fix: timeout on citgm tests by @simone-sanfratello in https://github.com/fastify/fastify/pull/5101
use strict directives by @Fdawgs in https://github.com/fastify/fastify/pull/5106Full Changelog: https://github.com/fastify/fastify/compare/v4.24.2...v4.24.3
fix: build problems when Symbol.asyncDispose type is not available. by @arthurfiorette in https://github.com/fastify/fastify/pull/5096
Symbol.asyncDispose type is not available. by @arthurfiorette in https://github.com/fastify/fastify/pull/5096Full Changelog: https://github.com/fastify/fastify/compare/v4.24.1...v4.24.2
fix: citgm by @simone-sanfratello in https://github.com/fastify/fastify/pull/5075
Full Changelog: https://github.com/fastify/fastify/compare/v4.24.0...v4.24.1
Your coding agent can read these notes before it upgrades. Set up the MCP server →