GHSA-p68q-wchp-6fh7

Suggest an improvement
Source
https://github.com/advisories/GHSA-p68q-wchp-6fh7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-p68q-wchp-6fh7/GHSA-p68q-wchp-6fh7.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-p68q-wchp-6fh7
Aliases
Published
2026-09-30T23:45:34Z
Modified
2026-10-01T00:00:05Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
Details

Impact

Fastify routes a malformed URL under one plugin prefix to the custom not-found handler of a different sibling plugin, invoking the handler registered last and skipping the preHandler declared in its setNotFoundHandler(). When the request method has no route in the main router, a malformed request target reaches Fastify's internal not-found router before URL decoding and is dispatched through a single shared handler pointer, regardless of prefix and without the normal request lifecycle. An unauthenticated request to a public prefix can therefore reach an authentication-protected not-found handler registered under a different prefix and receive its full response, breaking prefix encapsulation and bypassing the authentication hook. Applications whose private or tenant fallbacks return protected data from a not-found handler are affected.

Patches

Patched in fastify 5.12.2. Malformed URLs are now routed through the configured onBadUrl and onMaxParamLength handlers so they fail closed before any application not-found handler runs, and the shared not-found handler pointer has been removed.

Workarounds

Reject malformed request targets before they reach the application, for example at an upstream proxy or gateway, and do not rely on a not-found handler to serve protected data. A global onRequest authentication hook does not mitigate this, because the malformed-URL path skips it.

Database specific
{
    "cwe_ids": [
        "CWE-288"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-30T23:45:34Z",
    "nvd_published_at": "2026-09-04T10:17:12Z",
    "severity": "HIGH"
}
References

Affected packages

npm / fastify

Package

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
5.12.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-p68q-wchp-6fh7/GHSA-p68q-wchp-6fh7.json"