The CVE-2026-7120 vulnerability affects the @fastify/static module, allowing unauthenticated attackers to bypass path-based filtering by requesting equivalent non-canonical pathnames. This issue is patched in version 10.1.2. Developers and administrators should be aware of this vulnerability and take steps to mitigate it. The vulnerability has a CVSS score of 5.3 and is considered medium-severity. Affecte [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T04:16:31.980Z and has not been modified since then. The NVD entry is currently Analyzed. @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which onl [truncated]