PT-2026-94186 · Npm · Fastify-Static

·

CVE-2026-90982

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions @fastify/static versions prior to 10.1.4
Description On case-insensitive filesystems, such as Windows or default macOS volumes, a route guard or allowedPath restriction can be bypassed by altering the letter case of a path segment. This occurs because the route matcher is case-sensitive while the filesystem is not; a request with a modified case does not match the guarded route and is passed to the static handler, which the filesystem then resolves to the protected file. Consequently, unauthenticated requests can read files intended to be protected. This issue is not a directory traversal as it does not allow access to files outside the configured root, and it does not affect case-sensitive filesystems.
Recommendations Update to version 10.1.4. Serve static files from a case-sensitive filesystem. Ensure route guards and allowedPath rules account for every letter-case variant of the protected paths.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90982
GHSA-R799-R9GC-M956

Affected Products

Fastify-Static