
🚨 Critical-severity security fix in @fastify/express 4.0.7 just released! Patches CVE-2026-6556. @fastify/express vulnerable to middleware bypass via non-string mount paths in prefixed plugins. https://github.com/fastify/fastify-express/security/advisories/GHSA-3wf5-7852-vcfq
Post summary
Fastify Express releases version 4.0.7 with a critical fix for CVE‑2026‑6556, addressing a middleware bypass flaw; the advisory link provides further details.

