OsVault/npm/@fastify/express
npm

@fastify/express

3 known vulnerabilities · 0 critical · 0 high

GHSA-6hw5-45gm-fj88

@fastify/express has a middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)

Published Apr 16, 2026
CVE-2026-22037

@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)

Published Jan 20, 2026
GHSA-hrwm-hgmj-7p9c

@fastify/express's middleware path doubling causes authentication bypass in child plugin scopes

Published Apr 16, 2026
Check your entire dependency tree at onceRun dependency scan →