Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6414

23
FAUCET Score

CVE-2026-6414 is a path traversal vulnerability affecting @fastify/static versions 8.0.0 through 9.1.0. The flaw stems from a discrepancy in how percent-encoded path separators (%2F) are handled between the static file module and Fastify's router, allowing attackers to bypass route-based middleware and security guards that protect sensitive files. Users should upgrade to @fastify/static version 9.1.1 immediately, as no workarounds are available. The vulnerability carries a CVSS score of 5.9 (Medium severity) with a network attack vector and high attack complexity. While the impact is limited to confidentiality breaches with no integrity or availability concerns, the lack of authentication requirements means any unauthenticated network user could potentially exploit it. The attack requires specific conditions to succeed, reflected in the high complexity rating. There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list, and community attention remains minimal, as indicated by its inactive status on vulnerability hot lists. However, given the straightforward nature of path encoding techniques, organizations should treat this as a routine patching priority rather than an emergency response.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.0.0, < 9.1.1CPE matchmatch criteria
cpe:2.3:a:fastify:fastify-static:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 4th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

npmpatch availablevia ghsa
Product: @fastify/staticFixed in: 9.1.1

Vendor Advisories (1)

npmGHSA-x428-ghpx-8j92medium

@fastify/static vulnerable to route guard bypass via encoded path separators

Apr 16, 2026

References

cna.openjsf.org / security-advisories.html
Third Party Advisory
github.com / fastify/fastify-static/security/advisories/GHSA-x428-ghpx-8j92
Vendor Advisory
github.com / fastify/middie/security/advisories/GHSA-cxrg-g7r8-w69p
Not Applicable
github.com / honojs/hono/security/advisories/GHSA-q5qw-h33p-qvwr
Not Applicable