CVE-2026-76169: Authentication Bypass and Encapsulation Violation via Malformed URL Routing Fallback in Fastify
Vulnerability ID: CVE-2026-76169
CVSS Score: 7.5
Published: 2026-09-30
An authentication bypass vulnerability in the Fastify web framework allows remote attackers to access private custom not-found handlers by submitting requests with malformed URLs. This bypasses the typical request lifecycle and its associated authorization hooks.
TL;DR
Unauthenticated remote attackers can bypass route-level security hooks and access protected not-found handlers in sibling plugins by crafting malformed HTTP requests.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-288
- Attack Vector: Network
- CVSS Score: 7.5 (High)
- Exploit Status: poc
- KEV Status: No
Affected Systems
- Fastify applications utilizing prefix-encapsulated custom not-found handlers
-
fastify: >= 4.0.0, < 5.12.2 (Fixed in:
5.12.2)
Code Analysis
Commit: 93c239a
Fix: bad url routing fallback pointer leakage in four-oh-four handlers
Exploit Details
- GitHub: Official reproduction test cases are documented within the Fastify repository
Mitigation Strategies
- Upgrade Fastify package to version 5.12.2 or higher
- Configure front-end reverse proxies or WAFs to strictly validate URI structures and drop malformed percent-encoded sequences
- Avoid embedding sensitive information or logic inside custom not-found handlers
Remediation Steps:
- Run 'npm install fastify@latest' or the equivalent for your package manager
- Deploy and verify the updated dependencies in your testing and staging environments
- Confirm that requests containing invalid percent encoding return 400 Bad Request with FST_ERR_BAD_URL
References
- Fastify Security Advisory GHSA-p68q-wchp-6fh7
- Fix Commit in Fastify Repository
- Fastify Release v5.12.2
- NVD CVE-2026-76169 Detail Page
- OpenJS Foundation Security Advisories
Read the full report for CVE-2026-76169 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)