CVE-2026-2880Disclosure(fastify / fastify\/middie)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch fastify fastify\/middie systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example, app.use('/secret', auth)). When Fastify router normalization options are enabled (such as ignoreDuplicateSlashes, useSemicolonDelimiter, and related trailing-slash behavior), crafted request paths may bypass middleware checks while still being routed to protected handlers.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/middie

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
fastify\/middie

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-27: 2Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-27: 202-27
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in @fastify/middie@9.2.0 just released! Patches CVE-2026-2880 — vulnerable to a path normalization inconsistency that can result in authentication/authorization bypass when using path-scoped middleware. https://github.com/fastify/middie/security/advisories/GHSA-8p85-9qpw-fwgw

    Post summary

    The advisory announces a high‑severity patch for CVE‑2026‑2880, detailing a path normalization flaw that could bypass authentication, and provides a GitHub link to the fix.

    00010158
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2880 A vulnerability in @fastify/middie versions &lt; 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example, app.use('/secret',… https://www.cve.org/CVERecord?id=CVE-2026-2880

    Post summary

    The text announces a CVE‑2026‑2880 auth/authorization bypass in @fastify/middie versions below 9.2.0, with no PoC, exploit code, or patch information provided.

    0000092
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/middie-node.js-

Explore more