Disclosure summary
### Impact Fastify routes a malformed URL under one plugin prefix to the custom not-found handler of a different sibling plugin, invoking the handler registered last and skipping the `preHandler` declared in its `setNotFoundHandler()`. When the request method has no route in the main router, a malformed request target reaches Fastify's internal not-found router before URL decoding and is dispatched through a single shared handler pointer, regardless of prefix and without the normal request lifecycle. An unauthenticated request to a public prefix can therefore reach an authentication-protected not-found handler registered under a different prefix and receive its full response, breaking prefix encapsulation and bypassing the authentication hook. Applications whose private or tenant fallbacks return protected data from a not-found handler are affected. ### Patches Patched in fastify 5.12.2. Malformed URLs are now routed through the configured `onBadUrl` and `onMaxParamLength` handlers so they fail closed before any application not-found handler runs, and the shared not-found handler pointer has been removed. ### Workarounds Reject malformed request targets before they reach the applic
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-p68q-wchp-6fh7
Open original source · Updated Sep 30, 2026
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | fastify | >= 4.0.0, < 5.12.2 | 5.12.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T19:45:34-04:00
MODIFIED 2026-09-30T19:45:35-04:00
INGESTED 2026-10-06T11:45:02-04:00