{"id":"CVE-2026-2880","aliases":["GHSA-8p85-9qpw-fwgw"],"url":"https://o3.security/vulnerability/CVE-2026-2880","summary":"@fastify/middie has an improper path normalization vulnerability","details":"A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example, app.use('/secret', auth)).\n\nWhen Fastify router normalization options are enabled (such as ignoreDuplicateSlashes, useSemicolonDelimiter, and related trailing-slash behavior), crafted request paths may bypass middleware checks while still being routed to protected handlers.","published":"2026-02-27T18:25:37.428Z","modified":"2026-08-12T03:51:14.450411210Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@fastify/middie","fixedVersion":"9.2.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2880.json"},{"type":"ADVISORY","url":"https://github.com/fastify/middie/security/advisories/GHSA-8p85-9qpw-fwgw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2880"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:14.450411210Z"}}