{"id":"GHSA-p68q-wchp-6fh7","summary":"fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers","details":"### Impact\n\nFastify routes a malformed URL under one plugin prefix to the custom not-found handler of a different sibling plugin, invoking the handler registered last and skipping the `preHandler` declared in its `setNotFoundHandler()`. When the request method has no route in the main router, a malformed request target reaches Fastify's internal not-found router before URL decoding and is dispatched through a single shared handler pointer, regardless of prefix and without the normal request lifecycle. An unauthenticated request to a public prefix can therefore reach an authentication-protected not-found handler registered under a different prefix and receive its full response, breaking prefix encapsulation and bypassing the authentication hook. Applications whose private or tenant fallbacks return protected data from a not-found handler are affected.\n\n### Patches\n\nPatched in fastify 5.12.2. Malformed URLs are now routed through the configured `onBadUrl` and `onMaxParamLength` handlers so they fail closed before any application not-found handler runs, and the shared not-found handler pointer has been removed.\n\n### Workarounds\n\nReject malformed request targets before they reach the application, for example at an upstream proxy or gateway, and do not rely on a not-found handler to serve protected data. A global `onRequest` authentication hook does not mitigate this, because the malformed-URL path skips it.","aliases":["CVE-2026-76169"],"modified":"2026-10-01T00:00:05.203052898Z","published":"2026-09-30T23:45:34Z","database_specific":{"nvd_published_at":"2026-09-04T10:17:12Z","cwe_ids":["CWE-288"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-30T23:45:34Z"},"references":[{"type":"WEB","url":"https://github.com/fastify/fastify/security/advisories/GHSA-p68q-wchp-6fh7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76169"},{"type":"WEB","url":"https://github.com/fastify/fastify/commit/93c239a380f3f2778bb7565fcdf777e91cfe1fbc"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/fastify/fastify"},{"type":"WEB","url":"https://github.com/fastify/fastify/releases/tag/v5.12.2"}],"affected":[{"package":{"name":"fastify","ecosystem":"npm","purl":"pkg:npm/fastify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"5.12.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-p68q-wchp-6fh7/GHSA-p68q-wchp-6fh7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}