Executive brief
A vulnerability in the @fastify/middie library, which allows Fastify web applications to use traditional middleware, can lead to security bypasses. Because the library and the main web server disagree on how to read certain web addresses containing encoded slashes, security checks like login requirements or rate limits may be skipped. An attacker can exploit this to access restricted data or administrative functions without any prior authentication.
Technical details
An interpretation conflict (CWE-436) exists in @fastify/middie where the library decodes encoded slashes (%2F) within path parameters before matching middleware, while the underlying Fastify router preserves them. This discrepancy allows a crafted URL (e.g., /user/a%2Fb/comments) to bypass middleware intended for that path (e.g., /user/:id/comments) while still reaching the intended route handler. This bypass affects any security-critical middleware including authentication, authorization, and rate limiting. The vulnerability is reachable over the network without authentication. Users should upgrade to version 9.3.3 or move security logic to Fastify hooks like preHandler.
Affected products
- Fastify @fastify/middie 9.1.0 - 9.3.2
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-01: disclosed: NVD publication date
- 2026-07-01: patched: Version 9.3.3 released