mediumCVSS 5.3Vulnerability

CVE-2026-7120

### Impact `@fastify/static` evaluates the `allowedPath` callback before normalizing dot segments and duplicate slashes in the pathname used for file resolution. Non-canonical pathnames such as `//file`, `/./file`, or `/public/../private/file` bypass `allowedPath` filtering while resolving to the intended file on disk. Applications that use `allowedPath` as a security boundary to restrict access to specific static files or path subtrees may unintentionally expose files that were intended to be denied. ### Patches Upgrade to `@fastify/static` >= 10.1.2. ### Workarounds None. Upgrade to the patched version.

Properties

severity
medium
summary
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
epss_score
0.00369
cvss_score
5.3
ghsa_published
2026-07-24T16:43:44Z
source_url
https://github.com/advisories/GHSA-8pvw-jcv7-9cmj
ghsa_updated
2026-07-24T16:43:46Z
ghsa_id
GHSA-8pvw-jcv7-9cmj
cve_id
CVE-2026-7120
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
false
epss_percentile
0.3002

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Incorrect Behavior Order: Validate Before Canonicalize

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@fastify/static

AFFECTS (1)

[Software]npm/@fastify/static

Explore deeper with Ninja Signal's threat intelligence graph