Executive brief
@fastify/middie is a plugin for the Fastify web framework that allows developers to use Connect and Express middleware. A security flaw in how this plugin handles child components (plugins) causes security checks, such as authentication and authorization, to be silently skipped for certain web routes. This could allow unauthenticated attackers to access sensitive data or administrative functions that were intended to be protected.
Technical details
A vulnerability in @fastify/middie (v9.3.1 and earlier) occurs during the propagation of middleware from parent to child plugin scopes. When a child plugin is registered with a prefix that overlaps with a parent-scoped middleware path, the middleware path is incorrectly re-prefixed (doubled) during inheritance. This causes the middleware to fail to match incoming requests for routes defined within the child scope. Consequently, security-critical middleware—including authentication, authorization, and rate limiting—is silently bypassed. The issue is rooted in the onRegister function's handling of prefixed paths and is fixed in version 9.3.2.
Affected products
- Fastify @fastify/middie <= 9.3.1
Timeline
- 2026-04-16: disclosed
- 2026-04-16: advisory
- 2026-04-16: patched: Fixed in version 9.3.2