GHSA-6v32-fjc9-9qf6

Suggest an improvement
Source
https://github.com/advisories/GHSA-6v32-fjc9-9qf6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6v32-fjc9-9qf6/GHSA-6v32-fjc9-9qf6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6v32-fjc9-9qf6
Aliases
Published
2026-06-15T20:36:43Z
Modified
2026-07-18T17:30:30Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Nest: Middleware Bypass on Fastify via Trailing Slash
Details

Impact

An authentication bypass vulnerability exists in @nestjs/platform-fastify (confirmed on version 11.1.24, the latest available release at time of report). When middleware is registered through NestJS's MiddlewareConsumer.forRoutes() API on the Fastify adapter, an unauthenticated client can bypass the Nest middleware registered for that route by simply appending a trailing slash (/) to the request URL.

This bypass works on the default Fastify adapter configuration — no special router options need to be enabled. Applications using the standard CRUD route shape (GET /resource and GET /resource/:id) are affected when they protect those routes with MiddlewareConsumer.forRoutes() middleware.

Patches

Fixed in @nestjs/platform-fastify@11.1.24

References

Kudos goes to @a-tt-om

Database specific
{
    "cwe_ids":  [
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-15T20:36:43Z",
    "nvd_published_at":  "2026-06-22T22:16:49Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @nestjs/platform-fastify

Package

Name
@nestjs/platform-fastify
View open source insights on deps.dev
Purl
pkg:npm/%40nestjs/platform-fastify

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.1.24

Database specific

last_known_affected_version_range
"<= 11.1.23"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6v32-fjc9-9qf6/GHSA-6v32-fjc9-9qf6.json"