CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54281

highcovered by 1 sourcefirst seen 2026-06-15
Impact An authentication bypass vulnerability exists in @nestjs/platform-fastify (confirmed on version 11.1.24, the latest available release at time of report). When middleware is registered through NestJS's MiddlewareConsumer.forRoutes() API on the Fastify adapter, an unauthenticated client can bypass the Nest middleware registered for that route by simply appending a trailing slash (/) to the request URL. This bypass works on the default Fastify adapter configuration — no special router options need to be enabled. Applications using the standard CRUD route shape (GET /resource and GET /resource/:id) are affected when they protect those routes with MiddlewareConsumer.forRoutes() middleware. Patches Fixed in @nestjs/platform-fastify@11.1.24 References Kudos goes to @a-tt-om

⚡ Watch CVE-2026-54281

Get an email if CVE-2026-54281 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-54281

CVE.org record

Embed the live status

CVE-2026-54281 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54281 status](https://www.csirts.com/badge/CVE-2026-54281)](https://www.csirts.com/cve/CVE-2026-54281)