CVE-2026-7120
MEDIUMDescription
@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2.
Is your site exposed to CVE-2026-7120?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| fastify | fastify-static |
References
Frequently Asked Questions
What is CVE-2026-7120? +
How severe is CVE-2026-7120? +
What products are affected by CVE-2026-7120? +
How do I check if I'm vulnerable to CVE-2026-7120? +
Related Vulnerabilities
Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates …
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because …
The cohttp package before 6.3.0 for OCaml allows directory traversal.
A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious …
Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an …
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed …