Junglewise Threat Intelligence

CVE-2026-76169: Fastify authentication bypass via malformed URLs in encapsulated handlers

CVE-2026-76169 · Severity: high · CVSS 7.5 · Published 2026-09-04

Vendors: OpenJS Foundation.

Executive brief

Fastify is a popular Node.js web framework used to build HTTP APIs and web services. A vulnerability in versions 4.0.0 through 5.12.1 allows an attacker to send a malformed URL to a public API endpoint and reach authentication-protected private handlers registered under a different endpoint, bypassing security checks. This could expose sensitive data, tenant information, or private API responses to unauthorized access.

Technical details

This is an authentication bypass vulnerability (CWE-288) affecting Fastify's internal not-found request router. When a malformed (unparseable) request target is sent to an HTTP method with no registered route, the request reaches Fastify's encapsulated not-found router before URL decoding occurs. The router then dispatches the request through a single shared handler pointer regardless of the plugin prefix, causing it to invoke the most recently registered not-found handler across all prefixes. This skips the preHandler hook declared for the target handler and breaks prefix isolation. An unauthenticated attacker can send a malformed request to a public prefix and reach an authentication-protected not-found handler registered under a private/tenant prefix, receiving its full response. The vulnerability requires network access but no privileges or user interaction. Fastify 5.12.2 patches this by routing malformed URLs through onBadUrl and onMaxParamLength handlers before any application not-found handler runs.

Affected products

  • OpenJS Foundation Fastify >= 4.0.0, < 5.12.2

Timeline

  • 2026-09-04: disclosed: CVE-2026-76169 and GHSA-p68q-wchp-6fh7 published
  • 2026-09-04: patched: Patch released in Fastify 5.12.2

References