CVE-2026-14181Disclosure(fastify / fastify\/middie)

LOWCVSS 7.5 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch fastify fastify\/middie systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when incoming request paths contain malformed percent-encoded sequences. Inputs such as an incomplete percent escape or a truncated multibyte sequence cause the underlying decoder to throw synchronously, and the exception escapes the middie normalize step and terminates the Node.js process. The bypass affects applications that call middie.run directly on the standalone engine API, causing an immediate denial of service for all connected clients until restart. Applications using the Fastify plugin path are not affected because Fastifys error handler catches the exception. Patches: upgrade to @fastify/middie 9.3.3. Workarounds: migrate from the standalone engine API to the Fastify plugin path, where the framework error handler catches the exception.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/middie

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
fastify\/middie

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-07-01: 4Patch / Workaround · 2026-07-01: 2Technical Details · 2026-07-01: 407-01
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Node.js process crash via malformed URL decoding in @fastify/middie standalone engine (CVE-2026-14181) CVE-2026-14181 is a denial-of-service flaw in the @fastify/middie standalone engine’s URL normalization/decoding path when handling request URLs. The root cause is improper input validation and unhandled synchronous exceptions triggered by malformed percent-encoded sequences during decoding. An attacker can exploit this by sending a crafted HTTP request with an invalid percent-encoded path to any service that calls http://middie.run directly, requiring no authentication. Successful exploitation can crash the Node.js process, terminating active connections and causing service-wide denial of service. 👉 Affected: @fastify/middie 9.1.0–9.3.2 | Upgrade to 9.3.3

    Post summary

    CVE‑2026‑14181 is a denial‑of‑service flaw in @fastify/middie triggered by malformed percent‑encoded URLs that can crash Node.js processes; upgrading to version 9.3.3 resolves the issue.

    0000085
    232 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14181 @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when incoming request paths contain malformed perc… https://www.cve.org/CVERecord?id=CVE-2026-14181 ----- Traducción: CVE-2026-14181 @fa… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-14181 affecting @fastify/middie, noting a flaw in URL normalization for certain malformed requests, but provides no PoC, exploit, or mitigation details.

    0000025
    90 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14181 @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when incoming request paths contain malformed perc… https://www.cve.org/CVERecord?id=CVE-2026-14181

    Post summary

    The tweet announces a newly disclosed CVE affecting fastify/middie’s URL normalization, with no evidence of exploitation, patch, or PoC provided.

    000001.0K
    57.7K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in @fastify/middie@9.3.3 just released! Patches CVE-2026-14181: @fastify/middie standalone engine vulnerable to Denial of Service via malformed percent-encoded paths https://github.com/fastify/middie/security/advisories/GHSA-qcc9-jh8q-47vh

    Post summary

    The text announces a high‑severity patch for CVE‑2026‑14181 against Fastify Middie, detailing a DoS flaw and linking to the advisory, with no PoC or exploit code disclosed.

    00000170
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/middie-node.js-

Explore more