Fastify / Fastify-Static
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-18427 | @fastify/static vulnerable to route guard bypass via non-canonical path segments | HIGH | 7.5 | Aug 6, 2026 |
| CVE-2026-15074 | @fastify/static vulnerable to route guard bypass via path traversal | HIGH | 7.5 | Jul 23, 2026 |
| CVE-2026-7120 | @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths | MEDIUM | 5.3 | Jul 23, 2026 |
| CVE-2026-6410 | @fastify/static vulnerable to path traversal in directory listing | MEDIUM | 5.3 | Apr 16, 2026 |
| CVE-2026-6414 | @fastify/static vulnerable to route guard bypass via encoded path separators | MEDIUM | 5.9 | Apr 16, 2026 |
| CVE-2021-22963 | fastify-static: open redirect via an URL with double slash followed by a domain | MEDIUM | 6.1 | Oct 14, 2021 |
| CVE-2021-22964 | fastify-static: open redirect and DoS via an URL with double slash followed by a domain and with invalid characters | HIGH | 8.8 | Oct 14, 2021 |
Showing 1 to 7 of 7 CVEs