PT-2026-93764 · Npm · @Fastify/Auth

·

CVE-2026-92087

·

Published

2026-09-16

·

Updated

2026-09-30

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @fastify/auth versions 5.0.0 through 5.1.0
Description This plugin composes multiple authentication and authorization strategies into a single route guard. An issue exists when strategies are composed using the relation "or" option combined with the run "all" option, and one entry is a nested array acting as an AND group. In this scenario, the group is evaluated in an order-dependent manner where an earlier failing check is silently dropped, and the final result depends solely on the last check. This can lead to an authorization bypass where a request is authorized if it satisfies only the last member of an AND group. A similar order-dependent bypass occurs when the top-level relation is "and" and a nested group uses "or".
Recommendations Update to version 5.1.1 or later. Omit the run "all" option where it is not required. Order each AND group so its stricter check is evaluated last. Replace nested AND groups with an explicit top-level "and" composition.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92087
GHSA-7H52-2RWR-M76R

Affected Products

@Fastify/Auth