Skip to main content

Vendor/product archive

fastify / fastify-static CVEs

Beta · best-effort

6 CVEs tagged to fastify / fastify-static0 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-7120

Published Jul 23, 2026

@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and inclu…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-15074

Published Jul 23, 2026

@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6410

Published Apr 16, 2026

@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directories outside t…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6414

Published Apr 16, 2026

@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. T…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2021-22964

Published Oct 14, 2021

A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arbitrary websites via a double s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22963

Published Oct 14, 2021

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: h…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1