@fastify/static vulnerabilities
CVEs whose affected-version data names the @fastify/static package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-90982Medium· 5.3@fastify/static is a Fastify plugin that serves static files from a configured root directory
@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume, a route guard or allowedPath restrict…
▾ Sunlit@fastify/static · @fastify/staticEPSS 0.36%via NVD
CVE-2026-15074High· 7.5@fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to route guard bypass via path traversal
▾ Twilightfastify · @fastify/staticEPSS 0.67%via GHSA
CVE-2026-7120Medium· 5.3@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
▾ Sunlitfastify · @fastify/staticEPSS 0.37%via GHSA