Junglewise Threat Intelligence

CVE-2026-90982: @fastify/static route guard bypass via case-folding

CVE-2026-90982 · Severity: medium · CVSS 5.3 · Published 2026-09-17

Vendors: OpenJS Foundation.

Executive brief

@fastify/static is a Fastify plugin that serves static files from a protected root directory. On case-insensitive filesystems (Windows and macOS), attackers can bypass route guards and allowedPath restrictions by changing the letter case of a path segment—for example, requesting /DEEP/secret.txt instead of /deep/secret.txt to access files that should be protected. This allows unauthorized users to read sensitive files that administrators intended to restrict.

Technical details

The vulnerability stems from a case-sensitivity mismatch between the route matcher (case-sensitive) and the filesystem (case-insensitive on Windows and macOS). When a request arrives with altered casing, the route guard does not match and the request falls through to the static file handler, which resolves the case-folded filename to the protected file. The attacker gains access without authentication because the authorization check is performed against a different spelling than the one the filesystem resolves. The issue affects versions before 10.1.4 and is fixed by validating the requested path against its actual on-disk spelling before serving the file. The vulnerability only impacts case-insensitive filesystems and does not constitute directory traversal.

Affected products

  • OpenJS Foundation @fastify/static before 10.1.4

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Fixed in version 10.1.4

References