DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-76169: CVE-2026-76169: Authentication Bypass and Encapsulation Violation via Malformed URL Routing Fallback in Fastify

CVE-2026-76169: Authentication Bypass and Encapsulation Violation via Malformed URL Routing Fallback in Fastify

Vulnerability ID: CVE-2026-76169
CVSS Score: 7.5
Published: 2026-09-30

An authentication bypass vulnerability in the Fastify web framework allows remote attackers to access private custom not-found handlers by submitting requests with malformed URLs. This bypasses the typical request lifecycle and its associated authorization hooks.

TL;DR

Unauthenticated remote attackers can bypass route-level security hooks and access protected not-found handlers in sibling plugins by crafting malformed HTTP requests.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-288
  • Attack Vector: Network
  • CVSS Score: 7.5 (High)
  • Exploit Status: poc
  • KEV Status: No

Affected Systems

  • Fastify applications utilizing prefix-encapsulated custom not-found handlers
  • fastify: >= 4.0.0, < 5.12.2 (Fixed in: 5.12.2)

Code Analysis

Commit: 93c239a

Fix: bad url routing fallback pointer leakage in four-oh-four handlers

Exploit Details

  • GitHub: Official reproduction test cases are documented within the Fastify repository

Mitigation Strategies

  • Upgrade Fastify package to version 5.12.2 or higher
  • Configure front-end reverse proxies or WAFs to strictly validate URI structures and drop malformed percent-encoded sequences
  • Avoid embedding sensitive information or logic inside custom not-found handlers

Remediation Steps:

  1. Run 'npm install fastify@latest' or the equivalent for your package manager
  2. Deploy and verify the updated dependencies in your testing and staging environments
  3. Confirm that requests containing invalid percent encoding return 400 Bad Request with FST_ERR_BAD_URL

References


Read the full report for CVE-2026-76169 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)