
🚨High - @fastify/static Route-Guard Bypass via Dot-Dot Path Segments (CVE-2026-15074) @fastify/static (up to 10.1.0) fails to reject dot-dot (..) path segments before the file-resolution stage. Because the underlying send library normalizes dot segments before applying its own traversal guard, an unauthenticated attacker can bypass route-scoped middleware and read files inside the static root that sit under a guarded URL prefix. This is a bypass of the earlier CVE-2026-6414 fix, which only handled encoded forward slashes. It does not allow access outside the static root by itself - it defeats route-guard filtering only. CVSS 7.5, confidentiality impact. 👉Upgrade @fastify/static to 10.1.1.
Post summary
A new high‑severity route‑guard bypass vulnerability (CVE-2026-15074) was disclosed, detailing how dot‑dot path segments allow unauthenticated file read under static root, with a patch available in @fastify/static v10.1.1.



