


Perceptive Security
SOC/SIEM Consultancy

@fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. The middlew…
Published:
15 april 2026 om 22:00:00
Alert date:
16 april 2026 om 16:02:16
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
CVE-2026-33804 affects @fastify/middie versions 9.3.1 and earlier, allowing middleware bypass when the deprecated ignoreDuplicateSlashes option is enabled. The vulnerability stems from middleware path matching logic that doesn't account for duplicate slash normalization performed by Fastify's router. Attackers can use requests with duplicate slashes to bypass middleware authentication and authorization checks. Only applications using the deprecated ignoreDuplicateSlashes option are affected. The fix is available in @fastify/middie version 9.3.2, with no workarounds available except disabling the problematic option.
Technical details
Mitigation steps:
Affected products:
@fastify/middie
Fastify
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33804
https://cna.openjsf.org/security-advisories.html
https://github.com/fastify/middie/security/advisories/GHSA-v9ww-2j6r-98q6
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
