HIGH
GHSA-wf42-42fg-fg84
Nest Fastify HEAD Request Middleware Bypass
Quick fix
GHSA-wf42-42fg-fg84 — @nestjs/platform-fastify: upgrade to the fixed version with the command below.
npm install @nestjs/platform-fastify@11.1.16Details
### Impact
In a NestJS application using `@nestjs/platform-fastify`, GET middleware can be bypassed because Fastify automatically redirects HEAD requests to the corresponding GET handlers (if they exist).
As a result:
- Middleware will be completely skipped. - The HTTP response won't include a body (since the response is truncated when redirecting a HEAD request to a GET handler). - The actual handler will still be executed.
### Patches
Fixed in `@nestjs/platform-fastify@11.1.16`
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@nestjs/platform-fastify
Introduced in:
0Fixed in: 11.1.16Fix
npm install @nestjs/platform-fastify@11.1.16References
- https://github.com/nestjs/nest/security/advisories/GHSA-wf42-42fg-fg84[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-33011[ADVISORY]
- https://github.com/nestjs/nest/commit/cbdf737cd6e7cefa52d05ecea2ae4af95c464614[WEB]
- https://github.com/nestjs/nest[PACKAGE]
- https://github.com/nestjs/nest/releases/tag/v11.1.17[WEB]