Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
Description
Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnerable if it uses @nestjs/platform-fastify; relies on NestMiddleware (via MiddlewareConsumer) for security checks (authentication, authorization, etc.), or through app.use(); and applies middleware to specific routes using string paths or controllers (e.g., .forRoutes('admin')). Exploitation can result in unauthenticated users accessing protected routes, restricted administrative endpoints becoming accessible to lower-privileged users, and/or middleware performing sanitization or validation being skipped. This issue is patched in @nestjs/platform-fastify@11.1.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@nestjs/platform-fastifynpm | < 11.1.11 | 11.1.11 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-8wpr-639p-ccrjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-69211ghsaADVISORY
- github.com/nestjs/nest/commit/c4cedda15a05aafec1e6045b36b0335ab850e771ghsax_refsource_MISCWEB
- github.com/nestjs/nest/security/advisories/GHSA-8wpr-639p-ccrjghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.