CVE-2026-7120: @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

Published Jul 23, 2026
·
Updated

@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2.

Other sources

Impact

@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate slashes in the pathname used for file resolution. Non-canonical pathnames such as //file, /./file, or /public/../private/file bypass allowedPath filtering while resolving to the intended file on disk.

Applications that use allowedPath as a security boundary to restrict access to specific static files or path subtrees may unintentionally expose files that were intended to be denied.

Patches

Upgrade to @fastify/static >= 10.1.2.

Workarounds

None. Upgrade to the patched version.

GitHub

Affected Software

3 affected componentsFixes available
npm/@fastify/static<=10.1.1
npm/@fastify/static<=10.1.1
10.1.2
fastify fastify-static<10.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@fastify/static to a version that resolves this vulnerability.

    Fixed in 10.1.2
  2. Upgrade

    Upgrade @fastify/static to a version that resolves this vulnerability.

    Fixed in 10.1.2

Event History

Jul 23, 2026
CVE Published
via MITRE·02:48 AM
Data Sourced
via MITRE·02:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
Affected Software
Jul 24, 2026
Advisory Published
via GitHub·04:43 PM
Data Sourced
via GitHub·04:43 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-7120?

CVE-2026-7120 has a medium severity score of 5.3.

2

How do I fix CVE-2026-7120?

To fix CVE-2026-7120, upgrade @fastify/static to version 10.1.2 or later.

3

What does CVE-2026-7120 affect?

CVE-2026-7120 affects versions of @fastify/static up to and including 10.1.1.

4

What type of vulnerability is CVE-2026-7120?

CVE-2026-7120 is an authorization bypass vulnerability via non-canonical URL paths.

5

Who can exploit CVE-2026-7120?

CVE-2026-7120 can be exploited by unauthenticated attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203