Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-2293

Опубликовано: 27 фев. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13.

A flaw was found in NestJS. When a NestJS application uses @nestjs/platform-fastify with Fastify path-normalization options enabled, a remote attacker can exploit this to bypass authentication and authorization middleware. This bypass allows unauthorized access to protected resources, compromising the application's security controls.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-agent-installer-ui-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-551
https://bugzilla.redhat.com/show_bug.cgi?id=2443367nestjs: NestJS: Authentication bypass via Fastify path-normalization

EPSS

Процентиль: 43%
0.00211
Низкий

7.5 High

CVSS3

Связанные уязвимости

nvd
около 1 месяца назад

A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13.

github
28 дней назад

Nest has a Fastify URL Encoding Middleware Bypass

EPSS

Процентиль: 43%
0.00211
Низкий

7.5 High

CVSS3