HIGHVulnerability

CVE-2026-76169

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-76169
signal_observed_at
2026-09-16T01:21:39+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-04T10:17:12.020
last_modified
2026-09-15T20:07:46.700

Related Entities (3)

AFFECTS_PRODUCT (1)

[Product]

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Authentication Bypass Using an Alternate Path or Channel

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76169 — Ninja Signal Threat Intelligence | Ninja Signal