A path normalization inconsistency in @fastify/middie can result in authentication/authorization bypass when using path-scoped middleware (for example, app.use('/secret', auth)).
When Fastify router normalization options are enabled (such as ignoreDuplicateSlashes, useSemicolonDelimiter, and related trailing-slash behavior), crafted request paths may bypass middleware checks while still being routed to protected handlers.
An unauthenticated remote attacker can access endpoints intended to be protected by middleware-based auth/authorization controls by sending specially crafted URL paths (for example, //secret or /secret;foo=bar), depending on router option configuration.
This may lead to unauthorized access to protected functionality and data exposure.
@fastify/middie@9.1.0The issue is caused by canonicalization drift between:
@fastify/middie path matching for app.use('/prefix', ...), andBecause middleware and router did not always evaluate the same normalized path, auth middleware could be skipped while route resolution still succeeded.
Until patched version is deployed:
{
"cwe_ids": [
"CWE-20"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-28T02:47:17Z",
"nvd_published_at": "2026-02-27T19:16:12Z",
"severity": "HIGH"
}