Skip to main content
Vulnerability Database/CVE-2026-90982

CVE-2026-90982: Fastify Static Auth Bypass Vulnerability

CVE-2026-90982 is an authentication bypass flaw in @fastify/static that allows attackers to access protected files on case-insensitive filesystems. This post explains its technical details, affected versions, and mitigation steps.

Published:

CVE-2026-90982 Overview

CVE-2026-90982 affects @fastify/static, a Fastify plugin that serves static files from a configured root directory. Versions before 10.1.4 allow attackers to bypass route guards and allowedPath restrictions by altering the letter case of a path segment. On case-insensitive filesystems such as Windows or the default macOS volume, the case-sensitive route matcher fails to recognize the guarded path, while the filesystem still resolves the request to the same protected file. Unauthenticated requests can read files that route guards were configured to protect. The flaw is classified as [CWE-178] Improper Handling of Case Sensitivity.

Critical Impact

Unauthenticated attackers can retrieve access-restricted static files by changing the letter case of URL path segments on case-insensitive filesystems.

Affected Products

  • @fastify/static versions before 10.1.4
  • Deployments on Windows filesystems (NTFS default)
  • Deployments on macOS with default case-insensitive APFS volumes

Discovery Timeline

  • 2026-09-17 - CVE-2026-90982 published to NVD
  • 2026-09-17 - Last updated in NVD database

Technical Details for CVE-2026-90982

Vulnerability Analysis

The vulnerability arises from a mismatch between two layers of the request pipeline. Fastify's route matcher performs case-sensitive comparison when evaluating registered routes and their guards. The underlying filesystem on Windows and default macOS volumes performs case-insensitive lookups. An attacker who requests /Admin/secret.txt instead of /admin/secret.txt avoids the route guard registered against /admin/*. The request then falls through to the static file handler, which resolves the path against the filesystem and returns the same protected file.

This is not a directory traversal issue. The plugin still serves only files within the configured root. The bypass instead defeats authorization logic layered on top of the static handler. Any preHandler, onRequest, or allowedPath restriction that assumes canonical casing is affected.

Root Cause

The root cause is inconsistent case-handling semantics between the route resolver and the filesystem. The plugin trusted route matching to enforce access control without normalizing the path against its actual on-disk spelling before authorization. Any letter-case variant of a protected segment produces a distinct route key while resolving to the same file.

Attack Vector

Exploitation requires only a network request to a vulnerable Fastify server running on a case-insensitive filesystem. An unauthenticated attacker enumerates protected paths, alters the case of one or more segments, and issues an HTTP GET request. No authentication, user interaction, or elevated privileges are required. Refer to the GitHub Security Advisory GHSA-r799-r9gc-m956 for advisory-level details.

Detection Methods for CVE-2026-90982

Indicators of Compromise

  • HTTP access log entries containing mixed-case variants of paths that are normally protected, such as /Admin/, /PRIVATE/, or /Config.json.
  • Successful 200 responses to unauthenticated requests for files that should require authorization.
  • Repeated requests from a single client iterating case permutations of the same path segment.

Detection Strategies

  • Compare access log paths against the canonical casing of registered route guards and flag divergences.
  • Enable case-insensitive route matching in web application firewall (WAF) rules that mirror your Fastify guards.
  • Audit responses for sensitive file signatures returned without a prior authenticated session.

Monitoring Recommendations

  • Ingest Fastify access logs into a centralized analytics platform and alert on 2xx responses to guarded prefixes with non-canonical casing.
  • Track the ratio of unauthenticated requests reaching the static file handler versus the route guard.
  • Monitor for enumeration patterns from single source IPs against known protected directories.

How to Mitigate CVE-2026-90982

Immediate Actions Required

  • Upgrade @fastify/static to version 10.1.4 or later, which validates requested paths against their actual on-disk spelling and rejects case-aliased paths before authorization.
  • Inventory all Fastify deployments running on Windows or default macOS volumes and prioritize them for patching.
  • Review access logs for prior exploitation attempts using mixed-case variants of protected paths.

Patch Information

The issue is fixed in @fastify/static 10.1.4. The fix validates the requested path against its actual on-disk spelling and rejects case-aliased paths before authorization checks run. Update the dependency in package.json and redeploy affected applications. See the OpenJS Foundation Security Advisories for coordinated advisory information.

Workarounds

  • Serve static files from a case-sensitive filesystem, such as Linux ext4 or a case-sensitive APFS volume on macOS.
  • Extend route guards and allowedPath rules to explicitly enumerate every letter-case variant of the protected paths.
  • Place a reverse proxy in front of Fastify that normalizes request path casing before the request reaches the application.
bash
# Upgrade @fastify/static to the patched version
npm install @fastify/static@^10.1.4

# Verify the installed version
npm ls @fastify/static

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.