CVE-2026-18165Disclosure(fastify / fastify\/oauth2)

LOWCVSS 5.4 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch fastify fastify\/oauth2 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-side binding to the browser that began the flow. Any party able to write a cookie for the application's host, such as a sibling subdomain under the same registrable domain, can plant matching state and verifier cookies and complete an attacker-owned OAuth flow inside a victim's browser, silently signing the victim in to the attacker's account (login CSRF). It does not expose the victim's own account, credentials, or tokens. The issue is fixed in @fastify/oauth2 8.3.0, which adds an opt-in hostPrefixedCookies option. Users should upgrade to 8.3.0 and enable it, or bind state to a server-side session.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/oauth2

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
fastify\/oauth2

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-15: 4Patch / Workaround · 2026-08-15: 1Technical Details · 2026-08-15: 308-15
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • HOL@HashgraphOnline
    Disclosure

    BREAKING: CVE-2026-18165 affects @fastify/oauth2 7.2.0 through 8.2.0. A related host that can set cookies for the app can plant OAuth state and PKCE verifier values, then complete an attacker-owned login inside a victim browser. This is login CSRF. It does not expose the victim's own account or OAuth tokens. Details: https://hol.org/blog/cve-2026-18165-fastify-oauth2-login-csrf

    Post summary

    CVE-2026-18165 is a login CSRF flaw in Fastify's OAuth2 plugin that allows attackers to plant OAuth state and PKCE verifier cookies, facilitating hijacked logins, but it does not expose user tokens, and no patches, exploits, or active exploitation reports are mentioned.

    120801.5K
    19.2K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in @fastify/oauth2@8.3.0 just released! Patches CVE-2026-18165: @fastify/oauth2 vulnerable to login CSRF via plantable OAuth state cookies https://github.com/fastify/fastify-oauth2/security/advisories/GHSA-p8h8-rj28-m8q9

    Post summary

    Fastify’s oauth2 module (CVE‑2026‑18165) suffered a medium‑severity CSRF flaw, now fixed in v8.3.0 via a security advisory with the patch available.

    11020319
    5.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-18165 @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code… https://www.cve.org/CVERecord?id=CVE-2026-18165 ----- Traducción: CVE-2026-18165 @fa… https://infoflow.cloud`

    Post summary

    An OAuth 2.0 plugin vulnerability (CVE‑2026‑18165) was announced, highlighting state validation issues in specific plugin versions.

    0000036
    98 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-18165 @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code… https://www.cve.org/CVERecord?id=CVE-2026-18165

    Post summary

    The excerpt merely mentions CVE‑2026‑18165 affecting @fastify/oauth2, offering no substantive information on exploitation, fixes, or technical specifics.

    000001.3K
    57.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/oauth2-node.js-

Explore more