B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

CVE-2026-6556 - @fastify/express vulnerable to middleware bypass via non-string mount paths in prefixed plugins

CVE ID :CVE-2026-6556 Published : June 30, 2026, 12:48 p.m. | 2 hours, 23 minutes ago Description :@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular...

Original-Artikel öffnen Zurück zur Übersicht