{"id":"GHSA-8wpr-639p-ccrj","summary":"Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)","details":"A NestJS application is vulnerable if it meets all of the following criteria:\n\n1. Platform: Uses `@nestjs/platform-fastify`.\n2. Security Mechanism: Relies on `NestMiddleware` (via `MiddlewareConsumer`) for security checks (authentication, authorization, etc.), or through `app.use()`\n3. Routing: Applies middleware to specific routes using string paths or controllers (e.g., `.forRoutes('admin')`).\nExample Vulnerable Config:\n\n```ts\n// app.module.ts\nexport class AppModule implements NestModule {\n  configure(consumer: MiddlewareConsumer) {\n    consumer\n      .apply(AuthMiddleware) // Security check\n      .forRoutes('admin');   // Vulnerable: Path-based restriction\n  }\n}\n```\n\nAttack Vector:\n\n- Target Route: `/admin`\n- Middleware Path: `admin`\n- Attack Request: `GET /%61dmin`\n- Result: Middleware is skipped (no match on `%61dmin`), but controller for `/admin` is executed.\n\nConsequences:\n\n- Authentication Bypass: Unauthenticated users can access protected routes.\n- Authorization Bypass: Restricted administrative endpoints become accessible to lower-privileged users.\n- Input Validation Bypass: Middleware performing sanitization or validation can be skipped.\n\n### Patches\n\nPatched in `@nestjs/platform-fastify@11.1.11`\n\n### Resources\n\nCredit goes to Hacktron AI for reporting this issue.","aliases":["CVE-2025-69211"],"modified":"2025-12-30T15:42:33.016579Z","published":"2025-12-30T15:32:44Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-12-30T15:32:44Z","nvd_published_at":"2025-12-29T16:15:44Z","cwe_ids":["CWE-367"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/nestjs/nest/security/advisories/GHSA-8wpr-639p-ccrj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69211"},{"type":"WEB","url":"https://github.com/nestjs/nest/commit/c4cedda15a05aafec1e6045b36b0335ab850e771"},{"type":"PACKAGE","url":"https://github.com/nestjs/nest"}],"affected":[{"package":{"name":"@nestjs/platform-fastify","ecosystem":"npm","purl":"pkg:npm/%40nestjs/platform-fastify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.1.11"}]}],"database_specific":{"last_known_affected_version_range":"\u003c 11.1.10","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-8wpr-639p-ccrj/GHSA-8wpr-639p-ccrj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"}]}