PatchSiren

@fastify/static CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM @fastify/static CVE published 2026-07-23

CVE-2026-7120

The CVE-2026-7120 vulnerability affects the @fastify/static module, allowing unauthenticated attackers to bypass path-based filtering by requesting equivalent non-canonical pathnames. This issue is patched in version 10.1.2. Developers and administrators should be aware of this vulnerability and take steps to mitigate it. The vulnerability has a CVSS score of 5.3 and is considered medium-severity. Affecte [truncated]

HIGH @fastify/static CVE published 2026-07-23

CVE-2026-15074

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T04:16:31.980Z and has not been modified since then. The NVD entry is currently Analyzed. @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which onl [truncated]