VYPR

Middie

by Fastify

Source repositories

CVEs (3)

  • CVE-2026-14198CriJul 1, 2026
    risk 0.52cvss 9.1epss 0.00

    @fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching middleware paths, while Fastify's underlying router preserves the encoding during route lookup. The two layers disagree on the canonical request path, so the…

  • CVE-2026-22031HigJan 19, 2026
    risk 0.48cvss 8.4epss 0.00

    @fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 where middleware registered with a specific path prefix can be bypassed using URL-encoded characters (e.g., `/%61dmin`…

  • CVE-2026-14181HigJul 1, 2026
    risk 0.42cvss 7.5epss 0.00

    @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when incoming request paths contain malformed percent-encoded sequences. Inputs such as an incomplete percent escape or a truncated multibyte sequence cause the…