LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-6556

fastify · fastify\/express

Published
CVSS9.1
Severitycritical
WeaknessCWE-285
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular expressions) are left unprefixed inside prefixed plugin scopes, so middleware registered with those forms does not match the actual prefixed request path. Applications that use path-scoped middleware for authentication, authorization, rate limiting, or auditing on routes inside a prefixed scope can be bypassed by sending a request to the prefixed route, because Fastify still matches the route but the middleware is skipped. Patches: upgrade to @fastify/express 4.0.7. Workarounds: use string mount paths ins

References

← Back to the CVE Tracker

Our coverage of CVE-2026-6556

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-6556.