cvereports@_cvereportsDisclosure
The post announces a critical middleware bypass in @fastify/express (CVE‑2026‑33807) describing a path interpretation conflict affecting versions 4.0.4 and earlier, with no PoC, exploit, or evidence of active exploitation.
Infoflowcloud@infoflowcloudDisclosure
Specifies a path handling bug in @fastify/express v4.0.4 and earlier that results in duplicated middleware paths when child plugins inherit routes.
CVE@CVEnewDisclosure
The text discloses a path handling bug in fastify/express v4.0.4 and earlier, describing how middleware paths are doubled when inherited by child plugins.
PulsePatch.io@pulsepatchioDisclosure
The post announces a critical authentication bypass (CVE-2026-33807) in @fastify/express caused by path doubling affecting child plugin scopes, urging users to review usage and watch for an upcoming fix.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
Public disclosure of a middleware path bypass vulnerability affecting @fastify/express versions 4.0.4 and earlier.
Ulises Gascón@kom_256Patch
A critical security fix for @fastify/express 4.0.5 has been released, patching CVE‑2026‑33807 which involves middleware path doubling that allows authentication bypass in child plugin scopes.