OVERVIEW CVE-2026-33807 is a path handling vulnerability affecting @fastify/express versions 4.0.4 and earlier. The flaw resides in the onRegister function, which incorrectly duplicates middleware paths when child plugins are registered with matching prefixes. This causes Express middleware paths to become malformed and fail to match incoming requests. SEVERITY The vulnerability carries a CRITICAL CVSS score of 9.1 with an attack vector of Network, Low attack complexity, and no authentication or user interaction required. The impact is severe, enabling complete bypass of Express middleware security controls including authentication, authorization, and rate limiting mechanisms for all routes within affected child plugin scopes. The attack requires no special configuration or request crafting, making it trivial to exploit. Confidentiality and Integrity are rated as High impact; Availability is unaffected. EXPLOITATION STATUS CVE-2026-33807 is not currently listed on the Known Exploited Vulnerabilities catalog and shows no indicators of active exploitation in the wild. The EPSS score of 0.000220 indicates minimal probability of exploitation relative to other CVEs. Community attention is low, with no known public exploit code readily available. Organizations should prioritize patching by upgrading to @fastify/express v4.0.5 or later to eliminate the risk before active exploitation becomes viable.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.5CPE matchmatch criteria | cpe:2.3:a:fastify:fastify\/express:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.