THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-85184 (CRITICAL 9.1) — @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different

[NVD] CVE-2026-85184 (CRITICAL 9.1) — @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different

mednvdPublished 2026-09-04

CVE-2026-85184 CVSS: 9.1 CRITICAL Published: 2026-09-04T10:17:13.900

@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different strings, a request using an absolute-form target r

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85184