Junglewise Threat Intelligence

CVE-2026-2293: NestJS auth bypass in @nestjs/platform-fastify

CVE-2026-2293 · Severity: critical · CVSS 9.8 · Published 2026-02-27

Technologies: NestJS Nest, @nestjs/platform-fastify (npm). Vendors: NestJS, npm.

Executive brief

NestJS is a popular framework for building server-side web applications. A security flaw in its Fastify integration allows attackers to bypass security checks like login requirements or permission controls. This could lead to unauthorized access to sensitive data or administrative functions by simply manipulating the web address used to access the application.

Technical details

An authentication and authorization bypass vulnerability exists in NestJS when using the @nestjs/platform-fastify adapter. The issue stems from a discrepancy in how paths are handled between NestJS middleware and the underlying Fastify engine when path-normalization options are enabled (CWE-551). Specifically, an attacker can craft a URL that bypasses security guards or middleware but is still routed to a protected controller by the underlying engine. This allows unauthenticated remote attackers to access restricted endpoints. The vulnerability is addressed in NestJS version 11.1.14.

Affected products

  • nestjs nest.js 11.1.13

Timeline

  • 2026-02-17: patched: Version 11.1.14 released to fix the bypass
  • 2026-02-27: disclosed: Initial vulnerability disclosure and CVE assignment

References

Related threats