Interpretation Conflict in nest - #VU150164

 

Interpretation Conflict in nest - #VU150164

Published: September 16, 2026


Vulnerability identifier: #VU150164
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-436
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication or authorization.

The vulnerability exists due to an interpretation conflict in the Fastify adapter's path-scoped middleware matching when processing HTTP requests with absolute-form request targets. A remote attacker can send an HTTP request with an absolute-form request target to bypass authentication or authorization.

Only applications that bind middleware to specific paths through MiddlewareConsumer.forRoutes(...) or .exclude(...) are affected.


Affected software

nest

Remediation

Install security update from vendor's website.

nest - addressed in versions 11.2.4, 12.0.2

External References

Related Security Bulletins