
🚨 High - NestJS Fastify Middleware Bypass (CVE-2026-54281) A trailing slash on any request URL silently bypasses middleware guards in the @nestjs/platform-fastify adapter. Routes protected by auth middleware, rate limiting, or logging are fully exposed on default-configured apps - no credentials or special setup required. Affects all NestJS apps using the Fastify adapter with MiddlewareConsumer.forRoutes() (CVSS 8.7). 👉 Affected: @nestjs/platform-fastify ≤ 11.1.23 | Upgrade to 11.1.24
Post summary
High‑severity vulnerability in NestJS Fastify middleware bypass disclosed, with a clear patch available (upgrade to 11.1.24).
