Back

MEDIUM

Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)

Published Dec 29, 2025

Description

Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnerable if it uses `@nestjs/platform-fastify`; relies on `NestMiddleware` (via `MiddlewareConsumer`) for security checks (authentication, authorization, etc.), or through `app.use()`; and applies middleware to specific routes using string paths or controllers (e.g., `.forRoutes('admin')`). Exploitation can result in unauthenticated users accessing protected routes, restricted administrative endpoints becoming accessible to lower-privileged users, and/or middleware performing sanitization or validation being skipped. This issue is patched in `@nestjs/platform-fastify@11.1.11`.

Affected products

Remediation

Red Hat statement

This vulnerability is rated Important for Red Hat because it allows unauthorized access to protected routes in NestJS applications. In the Red Hat context, this impacts OpenShift Container Platform and Hosted OpenShift components that are configured to use `@nestjs/platform-fastify` and rely on `NestMiddleware` for security checks on specific routes.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Dec 29, 2025
Updated Dec 29, 2025
Reserved Dec 29, 2025
CISA Vulnrichment
Updated Dec 29, 2025
NVD
Status Analyzed
Modified Oct 5, 2026
Red Hat
Severity Important
Public date Dec 29, 2025
ENISA EUVD
Assigner GitHub_M
Published Dec 29, 2025
Updated Dec 29, 2025
Exploited since n/a
EUVD-2025-205611 GHSA-8WPR-639P-CCRJ