GHSA-8wpr-639p-ccrj
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
Quick fix
GHSA-8wpr-639p-ccrj — @nestjs/platform-fastify: upgrade to the fixed version with the command below.
npm install @nestjs/platform-fastify@11.1.11Details
A NestJS application is vulnerable if it meets all of the following criteria:
1. Platform: Uses `@nestjs/platform-fastify`. 2. Security Mechanism: Relies on `NestMiddleware` (via `MiddlewareConsumer`) for security checks (authentication, authorization, etc.), or through `app.use()` 3. Routing: Applies middleware to specific routes using string paths or controllers (e.g., `.forRoutes('admin')`). Example Vulnerable Config:
```ts // app.module.ts export class AppModule implements NestModule { configure(consumer: MiddlewareConsumer) { consumer .apply(AuthMiddleware) // Security check .forRoutes('admin'); // Vulnerable: Path-based restriction } } ```
Attack Vector:
- Target Route: `/admin` - Middleware Path: `admin` - Attack Request: `GET /%61dmin` - Result: Middleware is skipped (no match on `%61dmin`), but controller for `/admin` is executed.
Consequences:
- Authentication Bypass: Unauthenticated users can access protected routes. - Authorization Bypass: Restricted administrative endpoints become accessible to lower-privileged users. - Input Validation Bypass: Middleware performing sanitization or validation can be skipped.
### Patches
Patched in `@nestjs/platform-fastify@11.1.11`
### Resources
Credit goes to Hacktron AI for reporting this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 11.1.11npm install @nestjs/platform-fastify@11.1.11