
🚨 High-severity security fix in @fastify/middie@9.2.0 just released! Patches CVE-2026-2880 — vulnerable to a path normalization inconsistency that can result in authentication/authorization bypass when using path-scoped middleware. https://github.com/fastify/middie/security/advisories/GHSA-8p85-9qpw-fwgw
Post summary
The advisory announces a high‑severity patch for CVE‑2026‑2880, detailing a path normalization flaw that could bypass authentication, and provides a GitHub link to the fix.

