{"id":"CVE-2026-6270","aliases":["GHSA-72c6-fx6q-fr5w"],"url":"https://o3.security/vulnerability/CVE-2026-6270","summary":"@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes","details":"### Impact\n\n`@fastify/middie` v9.3.1 and earlier incorrectly re-prefixes middleware paths when propagating them to child plugin scopes. When a child plugin is registered with a prefix that overlaps with a parent-scoped middleware path, the middleware path is modified during inheritance and silently fails to match incoming requests.\n\nThis results in complete bypass of middleware security controls for all routes defined within affected child plugin scopes, including nested (grandchild) scopes. Authentication, authorization, rate limiting, and any other middleware-based security mechanisms are skipped. No special request crafting or configuration is required.\n\nThis is the same vulnerability class as [GHSA-hrwm-hgmj-7p9c](https://github.com/fastify/fastify-express/security/advisories/GHSA-hrwm-hgmj-7p9c) (CVE-2026-33807) in `@fastify/express`.\n\n### Patches\n\nUpgrade to `@fastify/middie` v9.3.2 or later.\n\n### Workarounds\n\nNone. Upgrade to the patched version.","published":"2026-04-16T13:44:46.322Z","modified":"2026-08-12T03:51:20.930165797Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.00498,"percentile":0.40056,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@fastify/middie","fixedVersion":"9.3.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6270.json"},{"type":"ADVISORY","url":"https://github.com/fastify/fastify-express/security/advisories/GHSA-hrwm-hgmj-7p9c"},{"type":"ADVISORY","url":"https://github.com/fastify/middie/security/advisories/GHSA-72c6-fx6q-fr5w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6270"},{"type":"PACKAGE","url":"https://github.com/fastify/middie"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:20.930165797Z"}}