CVE-2026-2880: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-2880 is an improper path normalization vulnerability in @fastify/middie (the Fastify middleware compatibility layer) that allows unauthenticated remote attackers to bypass authentication and authorization controls enforced via path-scoped middleware. All versions of @fastify/middie prior to 9.2.0 are affected, with version 9.1.0 confirmed vulnerable. The vulnerability was published on February 27, 2026, and a patch was released as version 9.2.0. It carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is a canonicalization drift (CWE-20: Improper Input Validation) between how @fastify/middie evaluates path prefixes for middleware matching (e.g., app.use('/secret', auth)) and how Fastify's underlying find-my-way router resolves routes after applying normalization options such as ignoreDuplicateSlashes, useSemicolonDelimiter, and trailing-slash handling. Because the middleware layer and the router do not always evaluate the same normalized path, a crafted request path (e.g., //secret or /secret;foo=bar) can pass through the middleware check unevaluated while still being successfully routed to the protected handler. Exploitation requires no authentication, no user interaction, and is remotely exploitable over the network, but does require that the target application has router normalization options enabled alongside path-scoped middleware guards (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to access endpoints and handlers that are intended to be protected by middleware-based authentication or authorization controls. This can result in unauthorized access to sensitive data and restricted functionality, with high integrity impact as attackers can interact with protected resources without credentials. Availability is not directly impacted, and the vulnerability's scope is limited to applications using @fastify/middie with router normalization options enabled and relying on path-scoped middleware for security enforcement (GitHub Advisory, Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.166%, indicating a low current probability of exploitation in the wild. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered and responsibly disclosed by Cristian Vargas of the Fluid Attacks Research Team, coordinated by Oscar Uribe (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify target applications built on Fastify that use @fastify/middie versions prior to 9.2.0 with router normalization options enabled (e.g., ignoreDuplicateSlashes: true, useSemicolonDelimiter: true). Look for endpoints protected by path-scoped middleware such as app.use('/secret', authMiddleware).
  2. Identify protected paths: Probe the application to enumerate protected route prefixes (e.g., /secret, /admin, /api/private) by observing authentication challenges or redirect behavior on normal requests.
  3. Craft bypass path: Construct a request path that exploits the normalization inconsistency. Depending on the enabled router options, use variants such as //secret (duplicate slash bypass) or /secret;foo=bar (semicolon delimiter bypass).
  4. Send crafted request: Issue an HTTP request to the crafted path (e.g., GET //secret/resource HTTP/1.1). The middleware layer fails to match the path prefix and skips the auth middleware, while the router normalizes the path and routes the request to the protected handler.
  5. Access protected resource: Receive the response from the protected handler without having passed authentication, gaining unauthorized access to sensitive data or functionality (GitHub Advisory).

Indicators of compromise

  • Network: HTTP requests to protected path prefixes using anomalous path variants such as double slashes (e.g., GET //secret/...) or semicolon-delimited paths (e.g., GET /secret;foo=bar/...) from unauthenticated clients.
  • Logs: Application access logs showing successful (2xx) responses to requests with malformed or non-standard path formats targeting routes that normally require authentication; absence of authentication log entries for those requests.
  • Logs: Requests to protected endpoints that do not trigger expected authentication middleware log entries or audit events, indicating the middleware was bypassed.
  • Application Behavior: Unexpected access to sensitive API responses or data from clients that have not completed an authentication flow (GitHub Advisory).

Mitigation and workarounds

Upgrade @fastify/middie to version 9.2.0 or later, which resolves the canonicalization drift between middleware path matching and router normalization (GitHub Advisory). If immediate upgrade is not feasible, apply the following interim mitigations: (1) avoid relying solely on path-scoped middie guards for authentication/authorization; (2) enforce authentication at the route-level handlers or Fastify hooks (e.g., preHandler) after router normalization; and (3) disable risky normalization options (ignoreDuplicateSlashes, useSemicolonDelimiter) if operationally feasible. Additionally, conduct a security audit of protected endpoints to identify any unauthorized access that may have occurred prior to patching.

Community reactions

The vulnerability was discovered by Cristian Vargas of the Fluid Attacks Research Team and coordinated through responsible disclosure by Oscar Uribe, following Fluid Attacks' published disclosure policy (GitHub Advisory). The advisory was published by Fastify maintainer mcollina on February 27, 2026. Red Hat tracked the vulnerability in their security advisory system (Red Hat). No significant broader media coverage or notable social media discussion beyond standard CVE tracking feeds has been observed.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management