cbcvebase.

Fastify Express vulnerabilities

3 known vulnerabilities affecting fastify/fastify_express.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3

Vulnerabilities

Page 1 of 1
CVE-2026-33808P2CRITICALCVSS 9.1fixed in 4.0.52026-04-15
CVE-2026-33808 [CRITICAL] CWE-436 CVE-2026-33808: Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express mid Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options are enabled. This allows complete bypass of path-scoped authentication middleware via duplicate slashes when ignoreDuplicateSlashes is enabled, or via semicolon delimiters when useSemicolonDelimiter
nvd
CVE-2026-33807P2CRITICALCVSS 9.1fixed in 4.0.52026-04-15
CVE-2026-33807 [CRITICAL] CWE-436 CVE-2026-33807: @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that cau @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is registered with a prefix that matches a middleware path, the middleware path is prefixed a second time, causing it to never match incoming requests. This resu
nvd
CVE-2026-6556P2CRITICALCVSS 9.1fixed in 4.0.72026-06-30
CVE-2026-6556 [CRITICAL] CWE-285 CVE-2026-6556: @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount path @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular expressions) are left unprefixed inside prefixed plugin scopes, so middleware registered with those forms does not match the actual prefixed request path. Applic
nvd
Fastify Express vulnerabilities | cvebase