CVE-2026-33804Disclosure(fastify / fastify\/middie)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch fastify fastify\/middie systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. The middleware path matching logic does not account for duplicate slash normalization performed by Fastify's router, allowing requests with duplicate slashes to bypass middleware authentication and authorization checks. This only affects applications using the deprecated ignoreDuplicateSlashes option. Upgrade to @fastify/middie 9.3.2 to fix this issue. There are no workarounds other than disabling the ignoreDuplicateSlashes option.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-436

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/middie

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-16); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
fastify\/middie

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-16: 2Mentions · 2026-04-17: 2Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-17: 204-1604-17
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-162
Disclosure1Patch1
2026-04-172
Disclosure2
Full discourse4 posts
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in @fastify/middie@9.3.2 just released! Patches CVE-2026-33804 — middleware bypass via deprecated ignoreDuplicateSlashes option https://github.com/fastify/middie/security/advisories/GHSA-v9ww-2j6r-98q6

    Post summary

    A high‑severity fix for CVE-2026-33804, affecting Fastify’s middie via the deprecated ignoreDuplicateSlashes option, has just been released.

    00020177
    5.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33804 @fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. The middleware pa… https://www.cve.org/CVERecord?id=CVE-2026-33804 ----- Traducción: CVE-2026-33804: la… http://infoflow.cloud`

    Post summary

    The tweet announces the discovery of CVE-2026-33804 affecting @fastapi/middie versions 9.3.1 and earlier due to a middleware bypass when the deprecated ignoreDuplicateSlashes option is enabled.

    0000025
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33804 @fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. The middleware pa… https://www.cve.org/CVERecord?id=CVE-2026-33804

    Post summary

    The post announces that @fastify/middie versions 9.3.1 and earlier are vulnerable to a middleware bypass when the deprecated ignoreDuplicateSlashes option is enabled, referencing CVE-2026-33804.

    0000087
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33804 Middleware Bypass in @fastify/middie 9.3.1 via Duplicate Slash No... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33804 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A middleware bypass vulnerability has been disclosed for @fastify/middie 9.3.1, triggered by a duplicate slash; detailed information is available on Vulmon.

    0000043
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/middie-node.js-

Explore more