CVE-2026-33808Disclosure(fastify / fastify\/express)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch fastify fastify\/express systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options are enabled. This allows complete bypass of path-scoped authentication middleware via duplicate slashes when ignoreDuplicateSlashes is enabled, or via semicolon delimiters when useSemicolonDelimiter is enabled. In both cases, Fastify router normalizes the URL and matches the route, but @fastify/express passes the original un-normalized URL to Express middleware, which fails to match and is skipped. An unauthenticated attacker can access protected routes by manipulating the URL path. PatchesUpgrade to @fastify/express v4.0.5 or later.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-436

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/express

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 2 mentions (2026-04-15); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
fastify\/express

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-15: 2Mentions · 2026-04-16: 1Mentions · 2026-04-28: 1Mentions · 2026-06-16: 1Mentions · 2026-06-18: 1Exploit Tool / Code · 2026-06-18: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-06-18: 1Technical Details · 2026-04-15: 2Technical Details · 2026-04-16: 1Technical Details · 2026-04-28: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-18: 104-1504-1604-2806-1606-18
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure1Patch1
2026-04-161
Disclosure1
2026-04-281
Disclosure1
2026-06-161
Disclosure1
2026-06-181
Disclosure1
Full discourse6 posts
  • Jesús Morán | AI Infra@jamoran1356
    Disclosure

    @fastify/express tiene bypass de auth crítico (CVSS 9.1). CVE-2026-33808: ✓ `/admin//users` pasa el middleware que protege `/admin/users` ✓ Duplicate slashes y `;` se preservan al delegar a Express ✓ v4.0.4 o anterior expuestas Actualiza + normaliza URLs.

    Post summary

    A critical authentication bypass in @fastify/express (CVE-2026-33808) is disclosed, detailing how duplicate slashes trigger a middleware bypass, and users are urged to update and normalize URLs to mitigate the flaw.

    0000084
    488 followersView on X
  • Jesús Morán | AI Infra@jamoran1356
    Disclosure

    @fastify/express tiene bypass de auth crítico (CVSS 9.1). CVE-2026-33808: ✓ `/admin//users` pasa el middleware que protege `/admin/users` ✓ Duplicate slashes y `;` se preservan al delegar a Express ✓ v4.0.4 o anterior expuestas Actualiza + normaliza URLs.

    Post summary

    Fastify‑Express v4.0.4 or earlier suffers a critical authentication bypass via duplicate slashes and semicolons, CVSS 9.1; update and URL normalization are recommended mitigations.

    0000045
    476 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-33808: CVE-2026-33808: Authentication Bypass via Path Normalization Drift in @fastify/express An interpretation conflict (CWE-436) in @fastify/express up to version 4.0.4 allows unauthenticated attackers to bypass path-scoped middleware. By e... https://cvereports.com/reports/CVE-2026-33808

    Post summary

    The post announces CVE-2026‑33808, detailing an authentication bypass in @fastify/express with associated CWE and affected versions, but offers no PoC, exploit code, or patch information.

    0000022
    36 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    The `@fastify/express` module is vulnerable to an authentication bypass (CVE-2026-33808) via URL normalization gaps. This may lead to unauthorized access. Monitor for official updates. #Nodejs #Fastify #AuthBypass https://www.pulsepatch.io/posts/cve-2026-33808-fastify-express-auth-bypass

    Post summary

    The tweet announces an authentication bypass vulnerability (CVE-2026-33808) in @fastify/express caused by URL normalization gaps and advises users to monitor for official updates.

    0000036
    12 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33808 Authentication Middleware Bypass in @fastify/express v4.0.4 via URL Norm... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33808 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces an authentication middleware bypass vulnerability in fastify/express v4.0.4, providing links to details but no PoC, exploit, or patch information.

    0000048
    4.0K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Critical-severity security fix in @fastify/express@4.0.5 just released! Patches CVE-2026-33808 — middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons) https://github.com/fastify/fastify-express/security/advisories/GHSA-6hw5-45gm-fj88

    Post summary

    Fastify Express has released a critical update that patches CVE-2026-33808, fixing an authentication bypass caused by URL normalization gaps.

    00000100
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/express-node.js-

Explore more