Executive brief
@fastify/static is a Fastify plugin that serves static files from a protected root directory. On case-insensitive filesystems (Windows and macOS), attackers can bypass route guards and allowedPath restrictions by changing the letter case of a path segment—for example, requesting /DEEP/secret.txt instead of /deep/secret.txt to access files that should be protected. This allows unauthorized users to read sensitive files that administrators intended to restrict.
Technical details
The vulnerability stems from a case-sensitivity mismatch between the route matcher (case-sensitive) and the filesystem (case-insensitive on Windows and macOS). When a request arrives with altered casing, the route guard does not match and the request falls through to the static file handler, which resolves the case-folded filename to the protected file. The attacker gains access without authentication because the authorization check is performed against a different spelling than the one the filesystem resolves. The issue affects versions before 10.1.4 and is fixed by validating the requested path against its actual on-disk spelling before serving the file. The vulnerability only impacts case-insensitive filesystems and does not constitute directory traversal.
Affected products
- OpenJS Foundation @fastify/static before 10.1.4
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Fixed in version 10.1.4