AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-76169.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

### Impact Fastify routes a malformed URL under one plugin prefix to the custom not-found handler of a different sibling plugin, invoking the handler registered last and skipping the `preHandler` declared in its `setNotFoundHandler()`. When the request method has no route in the main router, a malformed request target reaches Fastify's internal not-found router before URL decoding and is dispatched through a single shared handler pointer, regardless of prefix and without the normal request lifecycle. An unauthenticated request to a public prefix can therefore reach an authentication-protected not-found handler registered under a different prefix and receive its full response, breaking prefix encapsulation and bypassing the authentication hook. Applications whose private or tenant fallbacks return protected data from a not-found handler are affected. ### Patches Patched in fastify 5.12.2. Malformed URLs are now routed through the configured `onBadUrl` and `onMaxParamLength` handlers so they fail closed before any application not-found handler runs, and the shared not-found handler pointer has been removed. ### Workarounds Reject malformed request targets before they reach the applic

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-p68q-wchp-6fh7

Open original source · Updated Sep 30, 2026

fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
npmfastify>= 4.0.0, < 5.12.25.12.2

Original records & references

PUBLISHED 2026-09-30T19:45:34-04:00
MODIFIED 2026-09-30T19:45:35-04:00
INGESTED 2026-10-06T11:45:02-04:00