criticalCVSS 9.1Vulnerability

CVE-2026-6270

### Impact `@fastify/middie` v9.3.1 and earlier incorrectly re-prefixes middleware paths when propagating them to child plugin scopes. When a child plugin is registered with a prefix that overlaps with a parent-scoped middleware path, the middleware path is modified during inheritance and silently fails to match incoming requests. This results in complete bypass of middleware security controls for all routes defined within affected child plugin scopes, including nested (grandchild) scopes. Authentication, authorization, rate limiting, and any other middleware-based security mechanisms are skipped. No special request crafting or configuration is required. This is the same vulnerability class as [GHSA-hrwm-hgmj-7p9c](https://github.com/fastify/fastify-express/security/advisories/GHSA-hrwm-hgmj-7p9c) (CVE-2026-33807) in `@fastify/express`. ### Patches Upgrade to `@fastify/middie` v9.3.2 or later. ### Workarounds None. Upgrade to the patched version.

Properties

severity
critical
summary
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
epss_score
0.00498
cvss_score
9.1
ghsa_published
2026-04-16T22:29:04Z
source_url
https://github.com/advisories/GHSA-72c6-fx6q-fr5w
ghsa_updated
2026-04-16T22:29:06Z
ghsa_id
GHSA-72c6-fx6q-fr5w
cve_id
CVE-2026-6270
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
is_ghsa_only
false
epss_percentile
0.40731

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]npm/@fastify/middie

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]npm/@fastify/middie

HAS_WEAKNESS (1)

[Weakness]Interpretation Conflict

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-6270 (CVSS 9.1) — Ninja Signal Threat Intelligence | Ninja Signal