Two critical vulnerabilities have been disclosed in Fastify middleware integrations that can let requests reach protected application routes without triggering expected security checks. CVE-2026-6556 affects @fastify/express through version 4.0.6, where middleware mounted with non-string paths such as arrays or regular expressions inside prefixed plugins is forwarded to Express without the Fastify prefix rewrite. That mismatch can cause authentication, authorization, rate-limiting, and auditing middleware to be skipped on prefixed routes, potentially exposing endpoints to unauthenticated users.
A separate flaw, CVE-2026-14198, affects @fastify/middie versions 9.1.0 through 9.3.2 because encoded slashes (%2F) in path parameters are decoded before middleware path matching, while Fastify routing preserves the encoding. The resulting path canonicalization mismatch can bypass middleware on parameterized routes even though the target handler still executes, and the issue is described as HTTP method agnostic with no authentication required. Recommended remediation is to upgrade to @fastify/express 4.0.7 or later and @fastify/middie 9.3.3, while interim mitigations include using string-only middleware mount paths, avoiding parameterized middleware paths for security decisions, and enforcing access checks in route handlers or Fastify hooks after router resolution.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-14198 was published for a critical authorization bypass vulnerability in @fastify/middie affecting versions 9.1.0 through 9.3.2. The issue stems from encoded slash decoding in path parameters before middleware matching, and the recommended fix is upgrading to version 9.3.3.
CVE-2026-6556 was published for a critical middleware bypass vulnerability in @fastify/express affecting version 4.0.6 and earlier. The disclosure stated the issue could allow authentication, authorization, rate limiting, or auditing middleware to be skipped on prefixed routes and recommended upgrading to 4.0.7 or later.
A GitHub security advisory disclosed an authorization bypass vulnerability in @fastify/express affecting versions up to 4.0.6, caused by non-string mount paths in prefixed plugins not being rewritten correctly. The advisory also described using string paths instead of arrays or regexes in prefixed plugins as a workaround.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.