CVE-2026-7120

Source
https://cve.org/CVERecord?id=CVE-2026-7120
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7120.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-7120
Aliases
Downstream
Published
2026-07-23T02:48:35.120Z
Modified
2026-08-12T03:51:26.386658833Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
Details

@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2.

Database specific
{
    "cwe_ids": [
        "CWE-180"
    ],
    "cna_assigner": "openjs",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7120.json"
}
References

Affected packages

Git / github.com/fastify/fastify-static

Affected ranges

Type
GIT
Repo
https://github.com/fastify/fastify-static
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:fastify:fastify-static:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "10.1.2"
        }
    ]
}

Affected versions

3.*
3.2.0
v0.*
v0.1.0
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.2.0
v0.2.1
v0.3.0
v0.4.0
v0.4.1
v0.5.0
v0.6.0
v0.8.0
v0.9.0
v1.*
v1.0.0
v10.*
v10.0.0
v10.1.0
v10.1.1
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.4.0
v2.5.0
v2.5.1
v2.6.0
v2.7.0
v3.*
v3.0.0
v3.0.1
v3.1.0
v3.2.1
v3.3.0
v3.3.1
v3.4.0
v3.5.0
v4.*
v4.0.0
v4.0.1
v4.1.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.3.0
v4.4.0
v4.4.1
v4.4.2
v4.5.0
v4.6.0
v4.6.1
v5.*
v5.0.0
v5.0.1
v5.0.2
v6.*
v6.0.0
v6.1.0
v6.10.0
v6.10.1
v6.10.2
v6.11.0
v6.11.1
v6.11.2
v6.12.0
v6.2.0
v6.3.0
v6.4.0
v6.4.1
v6.5.0
v6.5.1
v6.6.0
v6.6.1
v6.7.0
v6.8.0
v6.9.0
v7.*
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v8.*
v8.0.0
v8.0.1
v8.0.2
v8.0.3
v8.0.4
v8.1.0
v8.1.1
v8.2.0
v8.3.0
v9.*
v9.0.0
v9.1.0
v9.1.1
v9.1.2
v9.1.3
v9.2.0
v9.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-7120.json"