Jesús Morán | AI Infra[verified]@jamoran1356Disclosure
A critical authentication bypass in @fastify/express (CVE-2026-33808) is disclosed, detailing how duplicate slashes trigger a middleware bypass, and users are urged to update and normalize URLs to mitigate the flaw.
Jesús Morán | AI Infra[verified]@jamoran1356Disclosure
Fastify‑Express v4.0.4 or earlier suffers a critical authentication bypass via duplicate slashes and semicolons, CVSS 9.1; update and URL normalization are recommended mitigations.
cvereports@_cvereportsDisclosure
The post announces CVE-2026‑33808, detailing an authentication bypass in @fastify/express with associated CWE and affected versions, but offers no PoC, exploit code, or patch information.
PulsePatch.io@pulsepatchioDisclosure
The tweet announces an authentication bypass vulnerability (CVE-2026-33808) in @fastify/express caused by URL normalization gaps and advises users to monitor for official updates.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The tweet announces an authentication middleware bypass vulnerability in fastify/express v4.0.4, providing links to details but no PoC, exploit, or patch information.
Ulises Gascón@kom_256Patch
Fastify Express has released a critical update that patches CVE-2026-33808, fixing an authentication bypass caused by URL normalization gaps.