CVE-2026-6414Disclosure(fastify / fastify-static)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fastify fastify-static systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. This mismatch allows attackers to bypass route-based middleware or guards that protect files served by @fastify/static. For example, a route guard on a protected path can be circumvented by encoding the path separator in the URL. Upgrade to @fastify/static 9.1.1 to fix this issue. There are no workarounds.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-177

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify-static

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-17); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
fastify-static

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-16: 1Mentions · 2026-04-17: 2Mentions · 2026-07-23: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-07-23: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 2Technical Details · 2026-07-23: 104-1604-1707-23
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-161
Patch1
2026-04-172
Disclosure1General1
2026-07-231
Disclosure1
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - @fastify/static Route-Guard Bypass via Dot-Dot Path Segments (CVE-2026-15074) @fastify/static (up to 10.1.0) fails to reject dot-dot (..) path segments before the file-resolution stage. Because the underlying send library normalizes dot segments before applying its own traversal guard, an unauthenticated attacker can bypass route-scoped middleware and read files inside the static root that sit under a guarded URL prefix. This is a bypass of the earlier CVE-2026-6414 fix, which only handled encoded forward slashes. It does not allow access outside the static root by itself - it defeats route-guard filtering only. CVSS 7.5, confidentiality impact. 👉Upgrade @fastify/static to 10.1.1.

    Post summary

    A new high‑severity route‑guard bypass vulnerability (CVE-2026-15074) was disclosed, detailing how dot‑dot path segments allow unauthenticated file read under static root, with a patch available in @fastify/static v10.1.1.

    0000089
    254 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6414 @fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal ch… https://www.cve.org/CVERecord?id=CVE-2026-6414 ----- Traducción: CVE-2026-6414 @fa… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-6414, a path traversal vulnerability in fastify/static that decodes percent-encoded path separators before filesystem resolution, and provides a link to the official CVE record.

    0000031
    71 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6414 @fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal ch… https://www.cve.org/CVERecord?id=CVE-2026-6414

    Post summary

    CVE-2026-6414 describes a path traversal issue in fastify/static where percent‑encoded slashes are mishandled, but no PoC, exploit, patch, or active exploitation is reported.

    00000133
    57.2K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in @fastify/static@9.1.1 just released! Patches CVE-2026-6414 — route guard bypass via encoded path separators https://github.com/fastify/fastify-static/security/advisories/GHSA-x428-ghpx-8j92

    Post summary

    Fastify has released a security fix for CVE‑2026‑6414, a route guard bypass vulnerability involving encoded path separators, with the patch now available for version 9.1.1.

    0000078
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify-static---

Explore more