CVE-2026-33011Disclosure(nestjs / nest)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nestjs nest systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS application using @nestjs/platform-fastify GET middleware can be bypassed because Fastify automatically redirects HEAD requests to the corresponding GET handlers (if they exist). As a result: middleware will be completely skipped, the HTTP response won't include a body (since the response is truncated when redirecting a HEAD request to a GET handler), and the actual handler will still be executed. This issue is fixed in version 11.1.16.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-670

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nest

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
nest

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-24: 103-2003-24
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure1Patch1
2026-03-241
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 NestJS, Middleware Bypass via HEAD Request Redirection, #CVE-2026-33011 (Medium) https://dailycve.com/nestjs-middleware-bypass-via-head-request-redirection-cve-2026-33011-medium/

    Post summary

    A brief announcement of CVE-2026-33011, a medium‑severity NestJS middleware bypass caused by HEAD request redirection, with a link to a daily CVE report.

    0000023
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33011 Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS application using @nestjs/platform-fastify GET mid… https://www.cve.org/CVERecord?id=CVE-2026-33011

    Post summary

    The post briefly announces CVE‑2026‑33011, noting affected NestJS versions but providing no PoC, exploit, mitigation, or technical details.

    0000082
    56.8K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-33011: NestJS apps using @nestjs/platform-fastify let HEAD calls bypass GET middleware, running handlers without checks. Upgrade to 11.1.16+ to stay secure. More details ➡️ https://volerion.com/vulnerabilities/CVE-2026-33011 #NestJS #NodeJS #AppSec

    Post summary

    The advisory highlights that HEAD requests in NestJS apps using @nestjs/platform-fastify bypass GET middleware, and recommends upgrading to v11.1.16+ with additional details available at the linked page.

    0000036
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnestjsnest-node.js-

Explore more