{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@nestjs/platform-fastify-12.0.0---12.0.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@nestjs/platform-fastify (\u003c 11.2.4)","@nestjs/platform-fastify (12.0.0 - 12.0.1)"],"_cs_severities":["high"],"_cs_tags":["middleware-bypass","web-application-security","nestjs","fastify","npm"],"_cs_type":"threat","_cs_vendors":["NestJS"],"content_html":"\u003cp\u003eA security vulnerability in the \u003ccode\u003e@nestjs/platform-fastify\u003c/code\u003e package (versions \u0026lt; 11.2.4 and 12.0.0 to 12.0.1) allows for the bypass of path-scoped middleware. The issue originates from inconsistent path normalization between the Fastify router and the middleware engine (a bundled fork of \u003ccode\u003e@fastify/middie\u003c/code\u003e). When an attacker crafts an HTTP request using an absolute-form request target (e.g., \u003ccode\u003eGET http://host/path HTTP/1.1\u003c/code\u003e) rather than the standard origin-form (\u003ccode\u003eGET /path HTTP/1.1\u003c/code\u003e), the middleware layer fails to recognize the path correctly. Consequently, requests reach their destination route handlers without triggering path-bound security controls such as authentication, authorization, or rate-limiting. This vulnerability is particularly critical for applications that rely solely on NestJS middleware to enforce access controls on sensitive API endpoints. The issue was addressed by ensuring consistent path resolution and updating the underlying middleware engine dependency to version 9.3.4.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify protected endpoints secured by NestJS middleware.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a raw HTTP request using an absolute-form target containing the target path.\u003c/li\u003e\n\u003cli\u003eAttacker bypasses reverse proxies if the proxy configuration does not rewrite absolute-form request targets.\u003c/li\u003e\n\u003cli\u003eThe Fastify router resolves the absolute-form request to the legitimate route handler, bypassing the middleware mismatch.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003e@nestjs/platform-fastify\u003c/code\u003e middleware engine receives the absolute-form target and fails to match the configured route path due to lack of normalization.\u003c/li\u003e\n\u003cli\u003eThe application executes the controller logic for the requested endpoint without triggering the authentication or authorization middleware.\u003c/li\u003e\n\u003cli\u003eAttacker successfully retrieves protected data or performs unauthorized actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in authentication or authorization bypass for specific API endpoints secured by NestJS middleware. This can lead to unauthorized data access, administrative command execution, or the circumvention of rate-limiting and logging controls. The impact is dependent on the sensitivity of the handlers protected by the bypassed middleware. Applications that rely on external perimeter security or reverse proxies that enforce origin-form rewriting are partially protected from this vector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@nestjs/platform-fastify\u003c/code\u003e to version 11.2.4 or 12.0.2 (recommended 11.2.5 or 12.0.3) to resolve the underlying path resolution mismatch.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, implement a validation hook on the Fastify instance to reject non-origin-form request targets before the application processes the request.\u003c/li\u003e\n\u003cli\u003eConfigure edge reverse proxies (such as Nginx or HAProxy) to rewrite incoming absolute-form request targets to origin-form to normalize traffic before it reaches the application.\u003c/li\u003e\n\u003cli\u003eUtilize the provided proof-of-concept script using Node.js net sockets to verify that current deployments reject non-standard request line formats.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T16:30:22Z","date_published":"2026-09-30T16:30:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nestjs-middleware-bypass/","summary":"An improper handling of absolute-form HTTP request targets in @nestjs/platform-fastify allows attackers to bypass path-scoped middleware by inducing a path resolution mismatch between the router and the middleware layer.","title":"Path-Scoped Middleware Bypass in @nestjs/platform-fastify","url":"https://feed.craftedsignal.io/briefs/2026-09-nestjs-middleware-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - @Nestjs/Platform-Fastify (12.0.0 - 12.0.1)","version":"https://jsonfeed.org/version/1.1"}