CVE-2026-85184

    Dashboard / Vulnerabilities / CVE-2026-85184

    CVE-2026-85184

    Published: 4 Sept 2026Last Modified: 17 Sept 2026

    Summary: @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target

    Details: @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different strings, a request using an absolute-form target reaches the route handler while the path-scoped middleware, such as authentication or authorization, is skipped. An unauthenticated network attacker can use this to bypass path-based access controls in a Fastify application that relies on middie for those controls. Users should upgrade to @fastify/middie 9.3.4 or later.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 8de54e35035cefa5ca13fd9f06c7b38185038a0e

    Affected versions

    v9.3.3
    v9.3.2
    v9.3.1
    v9.3.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-85184 | CVE-DB