Executive brief
@fastify/middie is a Fastify plugin that manages Express-style middleware in web applications. Versions 9.1.0 through 9.3.3 have a flaw where path-scoped middleware (such as authentication or authorization) can be bypassed by attackers using absolute-form HTTP request targets. This allows unauthenticated attackers to access protected routes that should be guarded by the middleware, potentially exposing sensitive data or compromising application security.
Technical details
The vulnerability is an interpretation conflict (CWE-436) where @fastify/middie evaluates path-scoped middleware matching against the raw request target, while the underlying Fastify router (find-my-way) resolves absolute-form targets to their path component before dispatching. An attacker sends a request with an absolute-form target like "GET http://anything/private/secrets" which bypasses middie's middleware check but matches the handler in the router, allowing access to protected routes. The attack requires only network access and no authentication. The vulnerability is patched in version 9.3.4 and later; workarounds involve enforcing authentication at the Fastify hook level (e.g., preHandler) which runs after route resolution.
Affected products
- OpenJS Foundation @fastify/middie >= 9.1.0, < 9.3.4
Timeline
- 2026-09-04: disclosed: CVE-2026-85184 published
- 2026-09-04: patched: Version 9.3.4 released with fix