VDB
Sign up
HIGH7.4

GHSA-v9ww-2j6r-98q6

@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option

Quick fix

GHSA-v9ww-2j6r-98q6 — @fastify/middie: upgrade to the fixed version with the command below.

npm install @fastify/middie@9.3.2

Details

### Impact

`@fastify/middie` v9.3.1 and earlier does not read the deprecated (but still functional) top-level `ignoreDuplicateSlashes` option, only reading from `routerOptions`. This creates a normalization gap: Fastify's router normalizes duplicate slashes but middie does not, allowing middleware bypass via URLs with duplicate leading slashes (e.g., `//admin/secret`).

This only affects applications using the deprecated top-level configuration style (`fastify({ ignoreDuplicateSlashes: true })`). Applications using `routerOptions: { ignoreDuplicateSlashes: true }` are not affected.

This is distinct from [GHSA-8p85-9qpw-fwgw](https://github.com/fastify/middie/security/advisories/GHSA-8p85-9qpw-fwgw) (CVE-2026-2880), which was patched in v9.2.0.

### Patches

Upgrade to `@fastify/middie` >= 9.3.2.

### Workarounds

Migrate from deprecated top-level `ignoreDuplicateSlashes: true` to `routerOptions: { ignoreDuplicateSlashes: true }`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@fastify/middie
Introduced in: 0Fixed in: 9.3.2
Fixnpm install @fastify/middie@9.3.2

References