Junglewise Threat Intelligence

CVE-2026-33804: Fastify @fastify/middie middleware bypass via duplicate slashes

CVE-2026-33804 · Severity: high · CVSS 7.4 · Published 2026-04-16

Technologies: Fastify Middie, @fastify/middie (npm). Vendors: Fastify, npm.

Executive brief

@fastify/middie is a software component used to add middleware support to the Fastify web framework. A security flaw exists where certain security checks, such as authentication or authorization, can be bypassed if the application is configured to ignore duplicate slashes in web addresses. An attacker could exploit this by using specially crafted URLs (e.g., starting with double slashes) to access restricted areas of a website without proper permission.

Technical details

A middleware bypass vulnerability exists in @fastify/middie due to an interpretation conflict (CWE-436) between the middleware and the Fastify router. When the deprecated top-level 'ignoreDuplicateSlashes: true' option is used, the Fastify router normalizes duplicate slashes in incoming requests, but the middie middleware does not. This discrepancy allows an attacker to craft requests with duplicate slashes (e.g., '//admin') that fail to match middleware path patterns (avoiding auth/authz checks) but are correctly routed to protected handlers by the framework. This issue specifically affects applications using the deprecated top-level configuration rather than the newer 'routerOptions' configuration. The vulnerability is addressed in version 9.3.2.

Affected products

  • Fastify @fastify/middie <= 9.3.1

Timeline

  • 2026-04-16: disclosed
  • 2026-04-16: advisory
  • 2026-04-16: patched

References

Related threats