CVE-2026-7120
Published Jul 23, 2026@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and inclu…
- evidence mentions
- 2
- Buzz score
- 21.0