Executive brief
@fastify/static is a Node.js plugin that serves static files in Fastify web applications. The plugin can be configured with route-based guards to prevent unauthenticated access to sensitive files in specific directories. Due to incomplete path normalization, attackers can bypass these guards by using alternative path forms (like double slashes, dot segments, or encoded dots) to access protected files without authentication, exposing their contents.
Technical details
This is a path traversal vulnerability (CWE-22) caused by incomplete canonicalization of file paths. The static file handler rejects only parent directory (..) segments but fails to normalize dot segments (.), double slashes (//), encoded dots (%2e), and backslashes before route matching and file serving. An unauthenticated attacker can craft non-canonical path requests (e.g., //deep/secret.txt, /./deep/secret.txt, or /%2e/deep/secret.txt) that bypass route guards because find-my-way does not normalize these segments during route matching, but the underlying send layer collapses them and serves the protected file. Applications that protect file subtrees using route-based middleware or guards are affected; those using the allowedPath option are not. The vulnerability is fixed in version 10.1.3 by canonicalizing the pathname and rejecting backslashes before routing and serving.
Affected products
- OpenJS Foundation @fastify/static before 10.1.3
Timeline
- 2026-08-06: disclosed: Vulnerability disclosed and CVE-2026-18427 assigned
- 2026-08-06: patched: Fixed in @fastify/static version 10.1.3