CVE Feed

    Dashboard / CVE / CVE-2026-33807

    CVE-2026-33807

    @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is registered with a prefix that matches a middleware path, the middleware path is prefixed a second time, causing it to never match incoming requests. This results in complete bypass of Express middleware security controls, including authentication, authorization, and rate limiting, for all routes defined within affected child plugin scopes. No special configuration or request crafting is required. Upgrade to @fastify/express v4.0.5 or later.

    Published:Apr 15, 2026
    Last Modified:Jun 1, 2026
    EPS:Apr 15, 2026
    EPSS Score:0.00031
    CVSS Score:9.1

    Affected Products

    Vendor
    Fastify
    Product
    Fastify-express
    Vendor
    Fastify
    Product
    Fastify\/express

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High