@fastify/middie is vulnerable to Authentication Bypass
91
Critical Risk
@fastify/middie decides whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different strings, a request using an absolute-form target reaches the route handler while path-scoped middleware such as authentication is skipped. The fix canonicalizes the request target before middleware path matching so both layers evaluate the same path.
You are affected if you are using a version that falls within the vulnerable range and rely on path-scoped middie middleware for access controls.
@fastify/middie is vulnerable to Authentication Bypass in versions 9.1.0 - 9.3.3.
Upgrade the @fastify/middie library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.