{"schema_version":1,"title":"Fastify-Express vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in Fastify-Express: 0 in the last 7 days and 1 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-6556, was published on 30 June 2026.","url":"https://junglewise.ai/threats/technologies/express","json_url":"https://junglewise.ai/threats/technologies/express.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/express","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":9,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":5},"latest":[{"cve":"CVE-2026-6556","cvss":9.1,"slug":"cve-2026-6556-fastify-fastify-express-middleware-bypass-via-non-string-mount","title":"Fastify @fastify/express middleware bypass via non-string mount paths","severity":"critical","exploited":false,"published_at":"2026-06-30T13:19:25.467+00:00","url":"https://junglewise.ai/threats/cve-2026-6556-fastify-fastify-express-middleware-bypass-via-non-string-mount"},{"cve":"CVE-2026-33808","cvss":9.1,"epss":0.0055,"slug":"cve-2026-33808-fastify-fastify-express-auth-bypass-via-url-normalization-gaps","title":"Fastify @fastify/express auth bypass via URL normalization gaps","severity":"critical","exploited":false,"published_at":"2026-04-15T10:16:48.453+00:00","url":"https://junglewise.ai/threats/cve-2026-33808-fastify-fastify-express-auth-bypass-via-url-normalization-gaps"},{"cve":"CVE-2026-33807","cvss":9.1,"epss":0.0053,"slug":"cve-2026-33807-fastify-fastify-express-middleware-bypass-in-child-plugin-scopes","title":"Fastify @fastify/express middleware bypass in child plugin scopes","severity":"critical","exploited":false,"published_at":"2026-04-15T10:16:48.31+00:00","url":"https://junglewise.ai/threats/cve-2026-33807-fastify-fastify-express-middleware-bypass-in-child-plugin-scopes"},{"cve":"CVE-2026-22037","cvss":3.1,"epss":0.0036,"slug":"cve-2026-22037-fastify-fastify-express-middleware-bypass-via-url-encoding","title":"Fastify @fastify/express middleware bypass via URL encoding","severity":"low","exploited":false,"published_at":"2026-01-20T16:35:21+00:00","url":"https://junglewise.ai/threats/cve-2026-22037-fastify-fastify-express-middleware-bypass-via-url-encoding"},{"cve":"CVE-2024-51999","cvss":4,"slug":"cve-2024-51999-express-extended-query-parser-prototype-pollution","title":"Express extended query parser prototype pollution","severity":"medium","exploited":false,"published_at":"2025-12-01T18:59:17+00:00","url":"https://junglewise.ai/threats/cve-2024-51999-express-extended-query-parser-prototype-pollution"},{"cve":"CVE-2024-10491","cvss":3.1,"epss":0.0044,"slug":"cve-2024-10491-express-resource-injection-in-link-header","title":"Express resource injection in Link header","severity":"low","exploited":false,"published_at":"2024-10-29T18:30:37+00:00","url":"https://junglewise.ai/threats/cve-2024-10491-express-resource-injection-in-link-header"},{"cve":"CVE-2024-9266","cvss":3.1,"epss":0.0046,"slug":"cve-2024-9266-express-open-redirect-vulnerability","title":"Express open redirect vulnerability","severity":"low","exploited":false,"published_at":"2024-10-03T21:31:05+00:00","url":"https://junglewise.ai/threats/cve-2024-9266-express-open-redirect-vulnerability"},{"cve":"CVE-2024-43796","cvss":3.1,"epss":0.0049,"slug":"cve-2024-43796-express-xss-via-response-redirect","title":"Express XSS via response.redirect()","severity":"low","exploited":false,"published_at":"2024-09-10T19:41:04+00:00","url":"https://junglewise.ai/threats/cve-2024-43796-express-xss-via-response-redirect"},{"cve":"CVE-2024-29041","cvss":3.1,"epss":0.0079,"slug":"cve-2024-29041-express-js-open-redirect-in-malformed-urls","title":"Express.js open redirect in malformed URLs","severity":"low","exploited":false,"published_at":"2024-03-25T19:40:26+00:00","url":"https://junglewise.ai/threats/cve-2024-29041-express-js-open-redirect-in-malformed-urls"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Fastify Http-Proxy","slug":"http-proxy","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/http-proxy"},{"name":"Fastify Middie","slug":"middie","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/middie"},{"name":"Fastify Reply-From","slug":"reply-from","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/reply-from"},{"name":"Fastify-Static","slug":"static","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/static"},{"name":"Fastify Multipart","slug":"multipart","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/multipart"}],"technology":{"hub":true,"name":"Fastify-Express","slug":"express","vendor":{"name":"Fastify","slug":"fastify","url":"https://junglewise.ai/threats/vendors/fastify"},"aliases":[],"category":"library","homepage":"https://fastify.dev/","repo_url":"https://github.com/fastify/fastify-express","description":"A plugin for Fastify that adds support for Express.js middleware and applications.","url":"https://junglewise.ai/threats/technologies/express"},"most_severe":[{"cve":"CVE-2026-33808","cvss":9.1,"epss":0.0055,"slug":"cve-2026-33808-fastify-fastify-express-auth-bypass-via-url-normalization-gaps","title":"Fastify @fastify/express auth bypass via URL normalization gaps","severity":"critical","exploited":false,"published_at":"2026-04-15T10:16:48.453+00:00","url":"https://junglewise.ai/threats/cve-2026-33808-fastify-fastify-express-auth-bypass-via-url-normalization-gaps"},{"cve":"CVE-2026-33807","cvss":9.1,"epss":0.0053,"slug":"cve-2026-33807-fastify-fastify-express-middleware-bypass-in-child-plugin-scopes","title":"Fastify @fastify/express middleware bypass in child plugin scopes","severity":"critical","exploited":false,"published_at":"2026-04-15T10:16:48.31+00:00","url":"https://junglewise.ai/threats/cve-2026-33807-fastify-fastify-express-middleware-bypass-in-child-plugin-scopes"},{"cve":"CVE-2026-6556","cvss":9.1,"slug":"cve-2026-6556-fastify-fastify-express-middleware-bypass-via-non-string-mount","title":"Fastify @fastify/express middleware bypass via non-string mount paths","severity":"critical","exploited":false,"published_at":"2026-06-30T13:19:25.467+00:00","url":"https://junglewise.ai/threats/cve-2026-6556-fastify-fastify-express-middleware-bypass-via-non-string-mount"},{"cve":"CVE-2024-51999","cvss":4,"slug":"cve-2024-51999-express-extended-query-parser-prototype-pollution","title":"Express extended query parser prototype pollution","severity":"medium","exploited":false,"published_at":"2025-12-01T18:59:17+00:00","url":"https://junglewise.ai/threats/cve-2024-51999-express-extended-query-parser-prototype-pollution"},{"cve":"CVE-2024-29041","cvss":3.1,"epss":0.0079,"slug":"cve-2024-29041-express-js-open-redirect-in-malformed-urls","title":"Express.js open redirect in malformed URLs","severity":"low","exploited":false,"published_at":"2024-03-25T19:40:26+00:00","url":"https://junglewise.ai/threats/cve-2024-29041-express-js-open-redirect-in-malformed-urls"},{"cve":"CVE-2024-43796","cvss":3.1,"epss":0.0049,"slug":"cve-2024-43796-express-xss-via-response-redirect","title":"Express XSS via response.redirect()","severity":"low","exploited":false,"published_at":"2024-09-10T19:41:04+00:00","url":"https://junglewise.ai/threats/cve-2024-43796-express-xss-via-response-redirect"},{"cve":"CVE-2024-9266","cvss":3.1,"epss":0.0046,"slug":"cve-2024-9266-express-open-redirect-vulnerability","title":"Express open redirect vulnerability","severity":"low","exploited":false,"published_at":"2024-10-03T21:31:05+00:00","url":"https://junglewise.ai/threats/cve-2024-9266-express-open-redirect-vulnerability"},{"cve":"CVE-2024-10491","cvss":3.1,"epss":0.0044,"slug":"cve-2024-10491-express-resource-injection-in-link-header","title":"Express resource injection in Link header","severity":"low","exploited":false,"published_at":"2024-10-29T18:30:37+00:00","url":"https://junglewise.ai/threats/cve-2024-10491-express-resource-injection-in-link-header"},{"cve":"CVE-2026-22037","cvss":3.1,"epss":0.0036,"slug":"cve-2026-22037-fastify-fastify-express-middleware-bypass-via-url-encoding","title":"Fastify @fastify/express middleware bypass via URL encoding","severity":"low","exploited":false,"published_at":"2026-01-20T16:35:21+00:00","url":"https://junglewise.ai/threats/cve-2026-22037-fastify-fastify-express-middleware-bypass-via-url-encoding"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}