Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
Published Dec 29, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.38%
Description
Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnerable if it uses `@nestjs/platform-fastify`; relies on `NestMiddleware` (via `MiddlewareConsumer`) for security checks (authentication, authorization, etc.), or through `app.use()`; and applies middleware to specific routes using string paths or controllers (e.g., `.forRoutes('admin')`). Exploitation can result in unauthenticated users accessing protected routes, restricted administrative endpoints becoming accessible to lower-privileged users, and/or middleware performing sanitization or validation being skipped. This issue is patched in `@nestjs/platform-fastify@11.1.11`.
Affected products
-
- Version < 11.1.11StatusaffectedConstraints-
- Version
No data.
Red Hat OpenShift Container Platform 4
openshift4/ose-agent-installer-ui-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-agent-installer-ui-rhel9 | Not affected | n/a |
@nestjs/platform-fastify
npm
Introduced 0 Fixed 11.1.11
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @nestjs/platform-fastify | 0 | 11.1.11 |
Remediation
Red Hat statement
This vulnerability is rated Important for Red Hat because it allows unauthorized access to protected routes in NestJS applications. In the Red Hat context, this impacts OpenShift Container Platform and Hosted OpenShift components that are configured to use `@nestjs/platform-fastify` and rely on `NestMiddleware` for security checks on specific routes.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2025-69211 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2425826 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205611 Advisory
- https://github.com/advisories/GHSA-8wpr-639p-ccrj Advisory
- https://github.com/nestjs/nest/commit/c4cedda15a05aafec1e6045b36b0335ab850e771 x_refsource_MISCPatch
- https://github.com/nestjs/nest/security/advisories/GHSA-8wpr-639p-ccrj x_refsource_CONFIRMExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-69211
- https://www.cve.org/CVERecord?id=CVE-2025-69211
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-69211 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2425826 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205611 | Advisory | |
| https://github.com/advisories/GHSA-8wpr-639p-ccrj | Advisory | |
| https://github.com/nestjs/nest/commit/c4cedda15a05aafec1e6045b36b0335ab850e771 | x_refsource_MISCPatch | |
| https://github.com/nestjs/nest/security/advisories/GHSA-8wpr-639p-ccrj | x_refsource_CONFIRMExploitVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-69211 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-69211 |
Change history (0)
No recorded changes yet.