THREAT OPS › Threat News › [NVD] CVE-2026-76169 (HIGH 7.5) — fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated ha
[NVD] CVE-2026-76169 (HIGH 7.5) — fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated ha
CVE-2026-76169 CVSS: 7.5 HIGH Published: 2026-09-04T10:17:12.020
fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single sha
Indicators of compromise
- CVE-2026-76169cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76169