CRITICAL 9.1 CVE-2026-85184 Published 4 Sept 2026

Fastify Middie Path-Based Access Control Bypass

Worried this affects one of your servers?

Fastify's @fastify/middie versions >= 9.1.0 and before 9.3.4 have a vulnerability that allows unauthenticated attackers to bypass path-based access controls.

This is due to a mismatch between the raw request target used by middie and the resolved path used by the Fastify router.

Users should upgrade to @fastify/middie 9.3.4 or later to mitigate this issue.

Reference: CVE-2026-85184 on NVD

← Back to Security News