Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33011

25
FAUCET Score

CVE-2026-33011 describes a high-severity middleware bypass vulnerability affecting NestJS applications utilizing @nestjs/platform-fastify GET middleware in versions 11.1.15 and below. This flaw allows an attacker to bypass security controls by sending a HEAD request, which Fastify automatically redirects to the GET handler, executing the handler without middleware processing and potentially leading to high integrity impact. Rated 7.5 HIGH, the vulnerability has a network attack vector, low complexity, requires no privileges or user interaction, and impacts data integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this issue. Organizations should upgrade to NestJS version 11.1.16 or higher to remediate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 11.1.16CPE matchmatch criteria
cpe:2.3:a:nestjs:nest:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.35%
Probability of exploitation in next 30 days
EPSS Percentile
27.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0035 is in the 8th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: @nestjs/platform-fastifyFixed in: 11.1.16

Vendor Advisories (1)

npmGHSA-wf42-42fg-fg84high

Nest Fastify HEAD Request Middleware Bypass

Mar 17, 2026

References

github.com / nestjs/nest/commit/cbdf737cd6e7cefa52d05ecea2ae4af95c464614
Patch
github.com / nestjs/nest/releases/tag/v11.1.17
ProductRelease Notes
github.com / nestjs/nest/security/advisories/GHSA-wf42-42fg-fg84
Vendor Advisory