{"id":"GHSA-6v32-fjc9-9qf6","summary":"Nest: Middleware Bypass on Fastify via Trailing Slash","details":"### Impact\n\nAn authentication bypass vulnerability exists in `@nestjs/platform-fastify` (confirmed on version `11.1.24`, the latest available release at time of report). When middleware is registered through NestJS's `MiddlewareConsumer.forRoutes()` API on the Fastify adapter, an unauthenticated client can bypass the Nest middleware registered for that route by simply appending a trailing slash (`/`) to the request URL.\n\nThis bypass works on the **default Fastify adapter configuration** — no special router options need to be enabled. Applications using the standard CRUD route shape (`GET /resource` and `GET /resource/:id`) are affected when they protect those routes with `MiddlewareConsumer.forRoutes()` middleware.\n\n### Patches\n\nFixed in `@nestjs/platform-fastify@11.1.24`\n\n### References\n\nKudos goes to @a-tt-om","aliases":["CVE-2026-54281"],"modified":"2026-07-18T17:30:30.681312997Z","published":"2026-06-15T20:36:43Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-15T20:36:43Z","nvd_published_at":"2026-06-22T22:16:49Z","cwe_ids":["CWE-863"]},"references":[{"type":"WEB","url":"https://github.com/nestjs/nest/security/advisories/GHSA-6v32-fjc9-9qf6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54281"},{"type":"PACKAGE","url":"https://github.com/nestjs/nest"}],"affected":[{"package":{"name":"@nestjs/platform-fastify","ecosystem":"npm","purl":"pkg:npm/%40nestjs/platform-fastify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.1.24"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 11.1.23","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6v32-fjc9-9qf6/GHSA-6v32-fjc9-9qf6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}