Vulnerability GHSA-wf42-42fg-fg84
High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
6 months ago
March 17, 2026 at 06:38 PM UTC
Nest Fastify HEAD Request Middleware Bypass
6.0.0-alpha.3 - 11.1.15
6.0.0-alpha.3 - 11.1.15
Summary
Nest Fastify HEAD Request Middleware Bypass
Details
Impact
In a NestJS application using @nestjs/platform-fastify, GET middleware can be bypassed because Fastify automatically redirects HEAD requests to the corresponding GET handlers (if they exist).
As a result:
- Middleware will be completely skipped.
- The HTTP response won't include a body (since the response is truncated when redirecting a HEAD request to a GET handler).
- The actual handler will still be executed.
Patches
Fixed in @nestjs/[email protected]
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 hours ago
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
6.0.0-alpha.3 - 11.2.3 and 12.0.0 - 12.0.1 GHSA-9c5c-9qcx-q35q
6.0.0-alpha.3 - 11.2.3 and 12.0.0 - 12.0.1 GHSA-9c5c-9qcx-q35q
High Risk
3 months ago
Nest: Middleware Bypass on Fastify via Trailing Slash
6.0.0-alpha.3 - 11.1.23 GHSA-6v32-fjc9-9qf6
6.0.0-alpha.3 - 11.1.23 GHSA-6v32-fjc9-9qf6
High Risk
7 months ago
Nest has a Fastify URL Encoding Middleware Bypass
6.0.0-alpha.3 - 11.1.13 GHSA-r4wm-x892-vjmx
6.0.0-alpha.3 - 11.1.13 GHSA-r4wm-x892-vjmx
Medium Risk
9 months ago
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
6.0.0-alpha.3 - 11.1.10 GHSA-8wpr-639p-ccrj
6.0.0-alpha.3 - 11.1.10 GHSA-8wpr-639p-ccrj
Impacted packages
Timeline
Published
6 months ago
March 17, 2026 at 06:38 PM UTC
Fixed (11.1.16)
6 months ago
March 05, 2026 at 01:21 PM UTC
Last Modified
6 months ago
March 20, 2026 at 09:37 PM UTC