Junglewise Threat Intelligence

CVE-2026-54281: NestJS authentication bypass in @nestjs/platform-fastify via trailing slash

CVE-2026-54281 · Severity: high · CVSS 4 · Published 2026-06-22

Technologies: NestJS Nest, @nestjs/platform-fastify (npm), NestJS Platform-Fastify. Vendors: NestJS, npm.

Executive brief

NestJS is a popular framework used to build web applications and APIs. A security flaw in its Fastify integration allows users to bypass security checks, such as login requirements, by simply adding a trailing slash to the end of a web address. This could allow unauthorized individuals to access sensitive data or perform actions they should not be allowed to do.

Technical details

An authentication bypass vulnerability exists in the @nestjs/platform-fastify package when using the Fastify adapter. The issue occurs when middleware is registered via the MiddlewareConsumer.forRoutes() API; the middleware fails to execute if a trailing slash (/) is appended to the request URL, even in default configurations. This allows an attacker to bypass security logic, such as authentication or authorization guards implemented as middleware, for standard CRUD routes. The root cause is an inconsistency in how the Fastify adapter matches routes with trailing slashes against registered middleware. The vulnerability is resolved in version 11.1.24.

Affected products

  • nestjs nest < 11.1.24
  • nestjs @nestjs/platform-fastify <= 11.1.23

Timeline

  • 2026-06-08: advisory: GitHub security advisory published
  • 2026-06-22: disclosed: NVD publication date
  • 2026-06-22: patched: Fix released in version 11.1.24

References

Related threats