{"id":"CVE-2026-54281","aliases":["GHSA-6v32-fjc9-9qf6"],"url":"https://o3.security/vulnerability/CVE-2026-54281","summary":"Nest: Middleware Bypass on Fastify via Trailing Slash","details":"### Impact\n\nAn authentication bypass vulnerability exists in `@nestjs/platform-fastify` (confirmed on version `11.1.24`, the latest available release at time of report). When middleware is registered through NestJS's `MiddlewareConsumer.forRoutes()` API on the Fastify adapter, an unauthenticated client can bypass the Nest middleware registered for that route by simply appending a trailing slash (`/`) to the request URL.\n\nThis bypass works on the **default Fastify adapter configuration** — no special router options need to be enabled. Applications using the standard CRUD route shape (`GET /resource` and `GET /resource/:id`) are affected when they protect those routes with `MiddlewareConsumer.forRoutes()` middleware.\n\n### Patches\n\nFixed in `@nestjs/platform-fastify@11.1.24`\n\n### References\n\nKudos goes to @a-tt-om","published":"2026-06-22T20:48:45.895Z","modified":"2026-08-12T03:51:13.487242555Z","cvss":null,"epss":{"score":0.00498,"percentile":0.40733,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@nestjs/platform-fastify","fixedVersion":"11.1.24"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54281.json"},{"type":"ADVISORY","url":"https://github.com/nestjs/nest/security/advisories/GHSA-6v32-fjc9-9qf6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54281"},{"type":"PACKAGE","url":"https://github.com/nestjs/nest"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.487242555Z"}}