
🚨 HIGH - Node.js process crash via malformed URL decoding in @fastify/middie standalone engine (CVE-2026-14181) CVE-2026-14181 is a denial-of-service flaw in the @fastify/middie standalone engine’s URL normalization/decoding path when handling request URLs. The root cause is improper input validation and unhandled synchronous exceptions triggered by malformed percent-encoded sequences during decoding. An attacker can exploit this by sending a crafted HTTP request with an invalid percent-encoded path to any service that calls http://middie.run directly, requiring no authentication. Successful exploitation can crash the Node.js process, terminating active connections and causing service-wide denial of service. 👉 Affected: @fastify/middie 9.1.0–9.3.2 | Upgrade to 9.3.3
Post summary
CVE‑2026‑14181 is a denial‑of‑service flaw in @fastify/middie triggered by malformed percent‑encoded URLs that can crash Node.js processes; upgrading to version 9.3.3 resolves the issue.



