top of page
perceptive_background_267k.jpg

@fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. The middlew…

Published:

15 april 2026 om 22:00:00

Alert date:

16 april 2026 om 16:02:16

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

CVE-2026-33804 affects @fastify/middie versions 9.3.1 and earlier, allowing middleware bypass when the deprecated ignoreDuplicateSlashes option is enabled. The vulnerability stems from middleware path matching logic that doesn't account for duplicate slash normalization performed by Fastify's router. Attackers can use requests with duplicate slashes to bypass middleware authentication and authorization checks. Only applications using the deprecated ignoreDuplicateSlashes option are affected. The fix is available in @fastify/middie version 9.3.2, with no workarounds available except disabling the problematic option.

Technical details

Mitigation steps:

Affected products:

@fastify/middie
Fastify

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page