CVE Database
/

CVE-2026-2880

Back to search

CVE-2026-2880

Published: Feb 27, 2026

Modified: Feb 27, 2026

PUBLISHED

Description

A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example, app.use('/secret', auth)). When Fastify router normalization options are enabled (such as ignoreDuplicateSlashes, useSemicolonDelimiter, and related trailing-slash behavior), crafted request paths may bypass middleware checks while still being routed to protected handlers.

VendorProductVersions

@fastify/middie

@fastify/middie

affected
0.0.0 - < 9.2.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2026-2880 - Security Vulnerability | QwikSec