{"id":"GHSA-wf42-42fg-fg84","summary":"Nest Fastify HEAD Request Middleware Bypass","details":"### Impact\n\nIn a NestJS application using `@nestjs/platform-fastify`, GET middleware can be bypassed because Fastify automatically redirects HEAD requests to the corresponding GET handlers (if they exist).\n\nAs a result:\n\n- Middleware will be completely skipped.\n- The HTTP response won't include a body (since the response is truncated when redirecting a HEAD request to a GET handler).\n- The actual handler will still be executed.\n\n### Patches\n\nFixed in `@nestjs/platform-fastify@11.1.16`","aliases":["CVE-2026-33011"],"modified":"2026-03-20T21:37:35.417540Z","published":"2026-03-17T18:38:38Z","database_specific":{"github_reviewed_at":"2026-03-17T18:38:38Z","nvd_published_at":"2026-03-20T05:16:15Z","cwe_ids":["CWE-670"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/nestjs/nest/security/advisories/GHSA-wf42-42fg-fg84"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33011"},{"type":"WEB","url":"https://github.com/nestjs/nest/commit/cbdf737cd6e7cefa52d05ecea2ae4af95c464614"},{"type":"PACKAGE","url":"https://github.com/nestjs/nest"},{"type":"WEB","url":"https://github.com/nestjs/nest/releases/tag/v11.1.17"}],"affected":[{"package":{"name":"@nestjs/platform-fastify","ecosystem":"npm","purl":"pkg:npm/%40nestjs/platform-fastify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.1.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-wf42-42fg-fg84/GHSA-wf42-42fg-fg84.json","last_known_affected_version_range":"\u003c= 11.1.15"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}