<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Nestjs/Platform-Fastify (12.0.0 - 12.0.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@nestjs/platform-fastify-12.0.0---12.0.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 16:30:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@nestjs/platform-fastify-12.0.0---12.0.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path-Scoped Middleware Bypass in @nestjs/platform-fastify</title><link>https://feed.craftedsignal.io/briefs/2026-09-nestjs-middleware-bypass/</link><pubDate>Wed, 30 Sep 2026 16:30:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-nestjs-middleware-bypass/</guid><description>An improper handling of absolute-form HTTP request targets in @nestjs/platform-fastify allows attackers to bypass path-scoped middleware by inducing a path resolution mismatch between the router and the middleware layer.</description><content:encoded><![CDATA[<p>A security vulnerability in the <code>@nestjs/platform-fastify</code> package (versions &lt; 11.2.4 and 12.0.0 to 12.0.1) allows for the bypass of path-scoped middleware. The issue originates from inconsistent path normalization between the Fastify router and the middleware engine (a bundled fork of <code>@fastify/middie</code>). When an attacker crafts an HTTP request using an absolute-form request target (e.g., <code>GET http://host/path HTTP/1.1</code>) rather than the standard origin-form (<code>GET /path HTTP/1.1</code>), the middleware layer fails to recognize the path correctly. Consequently, requests reach their destination route handlers without triggering path-bound security controls such as authentication, authorization, or rate-limiting. This vulnerability is particularly critical for applications that rely solely on NestJS middleware to enforce access controls on sensitive API endpoints. The issue was addressed by ensuring consistent path resolution and updating the underlying middleware engine dependency to version 9.3.4.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify protected endpoints secured by NestJS middleware.</li>
<li>Attacker crafts a raw HTTP request using an absolute-form target containing the target path.</li>
<li>Attacker bypasses reverse proxies if the proxy configuration does not rewrite absolute-form request targets.</li>
<li>The Fastify router resolves the absolute-form request to the legitimate route handler, bypassing the middleware mismatch.</li>
<li>The <code>@nestjs/platform-fastify</code> middleware engine receives the absolute-form target and fails to match the configured route path due to lack of normalization.</li>
<li>The application executes the controller logic for the requested endpoint without triggering the authentication or authorization middleware.</li>
<li>Attacker successfully retrieves protected data or performs unauthorized actions.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in authentication or authorization bypass for specific API endpoints secured by NestJS middleware. This can lead to unauthorized data access, administrative command execution, or the circumvention of rate-limiting and logging controls. The impact is dependent on the sensitivity of the handlers protected by the bypassed middleware. Applications that rely on external perimeter security or reverse proxies that enforce origin-form rewriting are partially protected from this vector.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade <code>@nestjs/platform-fastify</code> to version 11.2.4 or 12.0.2 (recommended 11.2.5 or 12.0.3) to resolve the underlying path resolution mismatch.</li>
<li>If an immediate upgrade is not possible, implement a validation hook on the Fastify instance to reject non-origin-form request targets before the application processes the request.</li>
<li>Configure edge reverse proxies (such as Nginx or HAProxy) to rewrite incoming absolute-form request targets to origin-form to normalize traffic before it reaches the application.</li>
<li>Utilize the provided proof-of-concept script using Node.js net sockets to verify that current deployments reject non-standard request line formats.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>middleware-bypass</category><category>web-application-security</category><category>nestjs</category><category>fastify</category><category>npm</category></item></channel></rss>