THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18427 (HIGH 7.5) — @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and

[NVD] CVE-2026-18427 (HIGH 7.5) — @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and

mednvdPublished 2026-08-06

CVE-2026-18427 CVSS: 7.5 HIGH Published: 2026-08-06T16:16:38.350

@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer. As a result, an

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18427