CVE-2026-33807Disclosure(fastify / fastify\/express)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fastify fastify\/express systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is registered with a prefix that matches a middleware path, the middleware path is prefixed a second time, causing it to never match incoming requests. This results in complete bypass of Express middleware security controls, including authentication, authorization, and rate limiting, for all routes defined within affected child plugin scopes. No special configuration or request crafting is required. Upgrade to @fastify/express v4.0.5 or later.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-436

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/express

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-16); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
fastify\/express

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-15: 2Mentions · 2026-04-16: 3Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-15: 2Technical Details · 2026-04-16: 3Technical Details · 2026-04-28: 104-1504-1604-28
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure1Patch1
2026-04-163
Disclosure3
2026-04-281
Disclosure1
Full discourse6 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-33807: CVE-2026-33807: Middleware Bypass via Path Interpretation Conflict in @fastify/express A critical vulnerability exists in @fastify/express versions 4.0.4 and earlier where an interpretation conflict causes middleware paths to be incorr... https://cvereports.com/reports/CVE-2026-33807

    Post summary

    The post announces a critical middleware bypass in @fastify/express (CVE‑2026‑33807) describing a path interpretation conflict affecting versions 4.0.4 and earlier, with no PoC, exploit, or evidence of active exploitation.

    0000023
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33807 @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins… https://www.cve.org/CVERecord?id=CVE-2026-33807 ----- Traducción: CVE-2026-33807, @f… http://infoflow.cloud`

    Post summary

    Specifies a path handling bug in @fastify/express v4.0.4 and earlier that results in duplicated middleware paths when child plugins inherit routes.

    0000030
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33807 @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins… https://www.cve.org/CVERecord?id=CVE-2026-33807

    Post summary

    The text discloses a path handling bug in fastify/express v4.0.4 and earlier, describing how middleware paths are doubled when inherited by child plugins.

    00000175
    57.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `@fastify/express` users: A critical authentication bypass (CVE-2026-33807) due to path doubling affects child plugin scopes. Review usage & monitor for fix. #NodeJS #Fastify #AuthBypass #Infosec https://www.pulsepatch.io/posts/cve-2026-33807-fastify-express-auth-bypass

    Post summary

    The post announces a critical authentication bypass (CVE-2026-33807) in @fastify/express caused by path doubling affecting child plugin scopes, urging users to review usage and watch for an upcoming fix.

    0000039
    12 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33807 Middleware Path Bypass in @fastify/express 4.0.4 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33807

    Post summary

    Public disclosure of a middleware path bypass vulnerability affecting @fastify/express versions 4.0.4 and earlier.

    0000043
    4.0K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Critical-severity security fix in @fastify/express@4.0.5 just released! Patches CVE-2026-33807 — middleware path doubling causes authentication bypass in child plugin scopes https://github.com/fastify/fastify-express/security/advisories/GHSA-hrwm-hgmj-7p9c

    Post summary

    A critical security fix for @fastify/express 4.0.5 has been released, patching CVE‑2026‑33807 which involves middleware path doubling that allows authentication bypass in child plugin scopes.

    0000097
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/express-node.js-

Explore more