Executive brief
NestJS is a popular framework used to build web applications and APIs. A security flaw in its Fastify integration allows users to bypass security checks, such as login requirements, by simply adding a trailing slash to the end of a web address. This could allow unauthorized individuals to access sensitive data or perform actions they should not be allowed to do.
Technical details
An authentication bypass vulnerability exists in the @nestjs/platform-fastify package when using the Fastify adapter. The issue occurs when middleware is registered via the MiddlewareConsumer.forRoutes() API; the middleware fails to execute if a trailing slash (/) is appended to the request URL, even in default configurations. This allows an attacker to bypass security logic, such as authentication or authorization guards implemented as middleware, for standard CRUD routes. The root cause is an inconsistency in how the Fastify adapter matches routes with trailing slashes against registered middleware. The vulnerability is resolved in version 11.1.24.
Affected products
- nestjs nest < 11.1.24
- nestjs @nestjs/platform-fastify <= 11.1.23
Timeline
- 2026-06-08: advisory: GitHub security advisory published
- 2026-06-22: disclosed: NVD publication date
- 2026-06-22: patched: Fix released in version 11.1.24