Vulnerability Description
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nestjs | Nest | 11.1.13 |
Related Weaknesses (CWE)
References
- https://fluidattacks.com/advisories/netonThird Party AdvisoryExploit
- https://github.com/nestjs/nest/Product
- https://github.com/nestjs/nest/releases/tag/v11.1.14Release Notes
FAQ
What is CVE-2026-2293?
CVE-2026-2293 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1...
How severe is CVE-2026-2293?
CVE-2026-2293 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-2293?
Check the references section above for vendor advisories and patch information. Affected products include: Nestjs Nest.