
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2880 is an improper path normalization vulnerability in @fastify/middie (the Fastify middleware compatibility layer) that allows unauthenticated remote attackers to bypass authentication and authorization controls enforced via path-scoped middleware. All versions of @fastify/middie prior to 9.2.0 are affected, with version 9.1.0 confirmed vulnerable. The vulnerability was published on February 27, 2026, and a patch was released as version 9.2.0. It carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Feedly).
The root cause is a canonicalization drift (CWE-20: Improper Input Validation) between how @fastify/middie evaluates path prefixes for middleware matching (e.g., app.use('/secret', auth)) and how Fastify's underlying find-my-way router resolves routes after applying normalization options such as ignoreDuplicateSlashes, useSemicolonDelimiter, and trailing-slash handling. Because the middleware layer and the router do not always evaluate the same normalized path, a crafted request path (e.g., //secret or /secret;foo=bar) can pass through the middleware check unevaluated while still being successfully routed to the protected handler. Exploitation requires no authentication, no user interaction, and is remotely exploitable over the network, but does require that the target application has router normalization options enabled alongside path-scoped middleware guards (GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to access endpoints and handlers that are intended to be protected by middleware-based authentication or authorization controls. This can result in unauthorized access to sensitive data and restricted functionality, with high integrity impact as attackers can interact with protected resources without credentials. Availability is not directly impacted, and the vulnerability's scope is limited to applications using @fastify/middie with router normalization options enabled and relying on path-scoped middleware for security enforcement (GitHub Advisory, Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.166%, indicating a low current probability of exploitation in the wild. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered and responsibly disclosed by Cristian Vargas of the Fluid Attacks Research Team, coordinated by Oscar Uribe (GitHub Advisory).
@fastify/middie versions prior to 9.2.0 with router normalization options enabled (e.g., ignoreDuplicateSlashes: true, useSemicolonDelimiter: true). Look for endpoints protected by path-scoped middleware such as app.use('/secret', authMiddleware)./secret, /admin, /api/private) by observing authentication challenges or redirect behavior on normal requests.//secret (duplicate slash bypass) or /secret;foo=bar (semicolon delimiter bypass).GET //secret/resource HTTP/1.1). The middleware layer fails to match the path prefix and skips the auth middleware, while the router normalizes the path and routes the request to the protected handler.GET //secret/...) or semicolon-delimited paths (e.g., GET /secret;foo=bar/...) from unauthenticated clients.Upgrade @fastify/middie to version 9.2.0 or later, which resolves the canonicalization drift between middleware path matching and router normalization (GitHub Advisory). If immediate upgrade is not feasible, apply the following interim mitigations: (1) avoid relying solely on path-scoped middie guards for authentication/authorization; (2) enforce authentication at the route-level handlers or Fastify hooks (e.g., preHandler) after router normalization; and (3) disable risky normalization options (ignoreDuplicateSlashes, useSemicolonDelimiter) if operationally feasible. Additionally, conduct a security audit of protected endpoints to identify any unauthorized access that may have occurred prior to patching.
The vulnerability was discovered by Cristian Vargas of the Fluid Attacks Research Team and coordinated through responsible disclosure by Oscar Uribe, following Fluid Attacks' published disclosure policy (GitHub Advisory). The advisory was published by Fastify maintainer mcollina on February 27, 2026. Red Hat tracked the vulnerability in their security advisory system (Red Hat). No significant broader media coverage or notable social media discussion beyond standard CVE tracking feeds has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."