CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-2293

Critical · CVSS 9.8

NestJS (@nestjs/platform-fastify) — Authentication/Authorization Middleware Bypass via Fastify Path Normalization

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-863, CWE-551

Description

A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13.

Search profile — drives PoC discovery

Symbols @nestjs/platform-fastifyFastifyAdapterpath-normalizationmiddlewareAuthGuardCanActivateuseGlobalGuardsuseGlobalInterceptorsaddContentTypeParserignoreTrailingSlashcaseSensitiveforceContentTypeSniffing
Keywords CVE-2026-2293NestJS Fastify auth bypassnestjs platform-fastify middleware bypassFastify path normalization bypassNestJS authentication bypassNestJS authorization bypassnestjs 11.1.13 vulnerabilityCWE-863 NestJSCWE-551 NestJSnestjs guard bypass fastifynestjs CVE-2026-2293 PoC
Versions: 11.1.13 (fixed in 11.1.14)

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z