PatchSiren

@fastify/oauth2 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM @fastify/oauth2 CVE published 2026-08-15

CVE-2026-18165

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T14:17:07.290Z and has not been modified since then. The @fastify/oauth2 plugin for Fastify has a login CSRF vulnerability in versions from 7.2.0 up to but not including 8.3.0. The issue allows an attacker to plant matching state and verifier cookies and complete an attacker-owned OAuth flow insid [truncated]