Vulnerability GHSA-6v32-fjc9-9qf6

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 15, 2026 at 08:36 PM UTC
Nest: Middleware Bypass on Fastify via Trailing Slash
6.0.0-alpha.3 - 11.1.23
6.0.0-alpha.3 - 11.1.23

Summary

Nest: Middleware Bypass on Fastify via Trailing Slash

Details

Impact

An authentication bypass vulnerability exists in @nestjs/platform-fastify (confirmed on version 11.1.24, the latest available release at time of report). When middleware is registered through NestJS's MiddlewareConsumer.forRoutes() API on the Fastify adapter, an unauthenticated client can bypass the Nest middleware registered for that route by simply appending a trailing slash (/) to the request URL.

This bypass works on the default Fastify adapter configuration — no special router options need to be enabled. Applications using the standard CRUD route shape (GET /resource and GET /resource/:id) are affected when they protect those routes with MiddlewareConsumer.forRoutes() middleware.

Patches

Fixed in @nestjs/[email protected]

References

Kudos goes to @a-tt-om

Impacted packages

Timeline

Published
3 months ago
June 15, 2026 at 08:36 PM UTC
Fixed (11.1.24)
4 months ago
May 25, 2026 at 08:19 AM UTC
Last Modified
2 months ago
July 18, 2026 at 05:30 PM UTC