CRITICAL
9.1 CVE-2026-85184 Published 4 Sept 2026
Fastify Middie Path-Based Access Control Bypass
Worried this affects one of your servers?
Fastify's @fastify/middie versions >= 9.1.0 and before 9.3.4 have a vulnerability that allows unauthenticated attackers to bypass path-based access controls.
This is due to a mismatch between the raw request target used by middie and the resolved path used by the Fastify router.
Users should upgrade to @fastify/middie 9.3.4 or later to mitigate this issue.
Reference: CVE-2026-85184 on NVD
← Back to Security News