Логотип exploitDog
bind:CVE-2025-69211
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-69211

Количество 2

Количество 2

nvd логотип

CVE-2025-69211

около 1 месяца назад

Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnerable if it uses `@nestjs/platform-fastify`; relies on `NestMiddleware` (via `MiddlewareConsumer`) for security checks (authentication, authorization, etc.), or through `app.use()`; and applies middleware to specific routes using string paths or controllers (e.g., `.forRoutes('admin')`). Exploitation can result in unauthenticated users accessing protected routes, restricted administrative endpoints becoming accessible to lower-privileged users, and/or middleware performing sanitization or validation being skipped. This issue is patched in `@nestjs/platform-fastify@11.1.11`.

EPSS: Низкий
github логотип

GHSA-8wpr-639p-ccrj

около 1 месяца назад

Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-69211

Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnerable if it uses `@nestjs/platform-fastify`; relies on `NestMiddleware` (via `MiddlewareConsumer`) for security checks (authentication, authorization, etc.), or through `app.use()`; and applies middleware to specific routes using string paths or controllers (e.g., `.forRoutes('admin')`). Exploitation can result in unauthenticated users accessing protected routes, restricted administrative endpoints becoming accessible to lower-privileged users, and/or middleware performing sanitization or validation being skipped. This issue is patched in `@nestjs/platform-fastify@11.1.11`.

0%
Низкий
около 1 месяца назад
github логотип
GHSA-8wpr-639p-ccrj

Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу