← Retour
CVE-2026-15074
high
CVSS 7.5
@fastify/static vulnerable to route guard bypass via path traversal
Résumé
@fastify/static vulnerable to route guard bypass via path traversal
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-15074** a été découverte dans fastify.
Des attaquants peuvent cibler un point d'entrée spécifique comme ``getPathnameForSend`` à distance pour détourner le produit.
Des informations confidentielles peuvent être exposées. Score CVSS : 7.5/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « fastify CVE-2026-15074 » sur le site de l'éditeur.
CVE-2026-15074 (fastify) — CWE-22 / CVSS v3 7.5
Vecteur d'attaque : distant (réseau) / non authentifié / sans interaction utilisateur
Surface d'attaque : `getPathnameForSend` / `decodeURI` / `encodeURI` / `path.normalize`
Versions affectées : `<= 10.1.0`
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
@fastify/staticにおけるパストラバーサル脆弱性
📍 Périmètre concerné
バージョン10.1.0までの@fastify/static
🔥 Gravité
認証されていない攻撃者が静的ルート内のファイルを読み取ることが可能
🔧 Comment corriger
@fastify/staticをバージョン10.1.1以降にアップデートする
🛡️ Contournement
情報なし
🔍 Détection
バージョン10.1.0以下を使用しているか確認する
Paquets affectés
npm
@fastify/static
[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.1.1"}]}]
Références
- patch ce714d77-add3-4f53-aff5-83d477b104bb
- patch ce714d77-add3-4f53-aff5-83d477b104bb
- web https://nvd.nist.gov/vuln/detail/CVE-2026-15074
- web https://github.com/fastify/fastify-static/commit/db4276f846ba56b21f93768cd6636ee5e2fc58b1
- web https://github.com/fastify/fastify-static/releases/tag/v10.1.1
- web https://github.com/advisories/GHSA-83w8-p2f5-377r