{"id":"CVE-2021-22963","details":"A redirect vulnerability in the fastify-static module version \u003c 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.","aliases":["GHSA-p6vg-p826-qp3v"],"modified":"2026-07-09T01:07:27.752381Z","published":"2021-10-14T15:15:08.877Z","references":[{"type":"REPORT","url":"https://hackerone.com/reports/1354255"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fastify/fastify-static","events":[{"introduced":"0"},{"fixed":"d97b2cf6a0353e784ad2674aaecd6508ac74130d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.2.4"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:fastify:fastify-static:*:*:*:*:*:*:*:*"}}],"versions":["v4.2.3","v4.2.2","v4.2.1","v4.2.0","v4.1.0","v4.0.1","v4.0.0","v3.5.0","v3.4.0","v3.3.1","v3.3.0","v3.2.1","3.2.0","v3.1.0","v3.0.1","v3.0.0","v2.7.0","v2.6.0","v2.5.1","v2.5.0","v2.4.0","v2.3.4","v2.3.3","v2.3.2","v2.3.1","v2.3.0","v2.2.0","v2.1.0","v1.0.0","v2.0.0","v0.14.0","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.9.0","v0.8.0","v0.6.0","v0.5.0","v0.4.1","v0.4.0","v0.3.0","v0.2.1","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22963.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}