Junglewise Threat Intelligence

CVE-2026-7120: Fastify @fastify/static authorization bypass via non-canonical paths

CVE-2026-7120 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Technologies: Fastify Static, @fastify/static (npm). Vendors: Fastify, npm.

Executive brief

A vulnerability in the @fastify/static library, which is used to serve files like images and scripts for web applications, could allow unauthorized access to restricted files. By using specially crafted web addresses with extra slashes or dots, an attacker can bypass security rules intended to keep certain files private. This could lead to the exposure of sensitive internal files or data that should not be publicly accessible.

Technical details

The @fastify/static plugin fails to canonicalize URL paths before executing the 'allowedPath' validation callback. This root cause allows attackers to use non-canonical pathnames (e.g., '//file', '/./file', or directory traversal sequences like '/public/../private/file') to bypass security filters that rely on the 'allowedPath' check. Because the validation occurs before dot segments and duplicate slashes are normalized, the filter may permit a path that later resolves to a restricted file on the disk. This is a remote, unauthenticated attack vector. The issue is fixed in version 10.1.2.

Affected products

  • Fastify @fastify/static <= 10.1.1

Timeline

  • 2026-07-22: disclosed
  • 2026-07-23: advisory: NVD publication
  • 2026-07-24: patched: GitHub Advisory published and reviewed

References

Related threats