Vulnerability GHSA-8wpr-639p-ccrj
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
9 months ago
December 30, 2025 at 03:32 PM UTC
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
6.0.0-alpha.3 - 11.1.10
6.0.0-alpha.3 - 11.1.10
Summary
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
Details
A NestJS application is vulnerable if it meets all of the following criteria:
- Platform: Uses
@nestjs/platform-fastify. - Security Mechanism: Relies on
NestMiddleware(viaMiddlewareConsumer) for security checks (authentication, authorization, etc.), or throughapp.use() - Routing: Applies middleware to specific routes using string paths or controllers (e.g.,
.forRoutes('admin')). Example Vulnerable Config:
// app.module.ts
export class AppModule implements NestModule {
configure(consumer: MiddlewareConsumer) {
consumer
.apply(AuthMiddleware) // Security check
.forRoutes('admin'); // Vulnerable: Path-based restriction
}
}
Attack Vector:
- Target Route:
/admin - Middleware Path:
admin - Attack Request:
GET /%61dmin - Result: Middleware is skipped (no match on
%61dmin), but controller for/adminis executed.
Consequences:
- Authentication Bypass: Unauthenticated users can access protected routes.
- Authorization Bypass: Restricted administrative endpoints become accessible to lower-privileged users.
- Input Validation Bypass: Middleware performing sanitization or validation can be skipped.
Patches
Patched in @nestjs/[email protected]
Resources
Credit goes to Hacktron AI for reporting this issue.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 hours ago
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
6.0.0-alpha.3 - 11.2.3 and 12.0.0 - 12.0.1 GHSA-9c5c-9qcx-q35q
6.0.0-alpha.3 - 11.2.3 and 12.0.0 - 12.0.1 GHSA-9c5c-9qcx-q35q
High Risk
3 months ago
Nest: Middleware Bypass on Fastify via Trailing Slash
6.0.0-alpha.3 - 11.1.23 GHSA-6v32-fjc9-9qf6
6.0.0-alpha.3 - 11.1.23 GHSA-6v32-fjc9-9qf6
High Risk
6 months ago
Nest Fastify HEAD Request Middleware Bypass
6.0.0-alpha.3 - 11.1.15 GHSA-wf42-42fg-fg84
6.0.0-alpha.3 - 11.1.15 GHSA-wf42-42fg-fg84
High Risk
7 months ago
Nest has a Fastify URL Encoding Middleware Bypass
6.0.0-alpha.3 - 11.1.13 GHSA-r4wm-x892-vjmx
6.0.0-alpha.3 - 11.1.13 GHSA-r4wm-x892-vjmx
Impacted packages
Timeline
Published
9 months ago
December 30, 2025 at 03:32 PM UTC
Fixed (11.1.11)
9 months ago
December 29, 2025 at 01:31 PM UTC
Last Modified
9 months ago
December 30, 2025 at 03:42 PM UTC