vendor
fastify
Severity
Its products
Being told
The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.
Every thing
| @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target… CVE-2026-85184 | Severity critical |
| fastify: fastify: Unauthorized state changes and data disclosure via request body replacement CVE-2026-84504 | Severity high |
| fastify: Fastify: Request validation bypass allows unauthorized operations CVE-2026-84469 | Severity high |
| fastify: fastify: Header validation bypass via incomplete schema case normalization CVE-2026-84428 | Severity high |
| fastify: fastify: Authentication bypass via malformed URLs CVE-2026-76169 | Severity high |