THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-76169 (HIGH 7.5) — fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated ha

[NVD] CVE-2026-76169 (HIGH 7.5) — fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated ha

mednvdPublished 2026-09-04

CVE-2026-76169 CVSS: 7.5 HIGH Published: 2026-09-04T10:17:12.020

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single sha

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-76169