chore(deps): update dependency @nestjs/platform-fastify to v12.0.2 [security] - #2784
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
12.0.1→12.0.2@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
GHSA-9c5c-9qcx-q35q
More information
Details
@nestjs/platform-fastify>= 12.0.0, < 12.0.2and< 11.2.412.0.2and11.2.4(upgrade to12.0.3/11.2.5)Summary
On the Fastify adapter, an HTTP request that uses an absolute-form request target (
GET http://host/path HTTP/1.1instead of
GET /path HTTP/1.1) reaches the route handler without running the path-scoped Nest middleware bound tothat route. Applications that enforce authentication or authorization in middleware execute the protected handler
with those checks skipped.
Impact
Any application that
@nestjs/platform-fastify, andMiddlewareConsumer.forRoutes(...)or.exclude(...), andNode's HTTP server accepts absolute-form targets, so no special server configuration is needed. Exposure is reduced
when a reverse proxy in front of the application rewrites the request target to origin-form, which most do.
Where the bypassed middleware performs authentication or authorization, the result is an authentication or
authorization bypass. Where it performs logging, rate limiting or body handling, those are silently skipped instead.
Details
Fastify's router (
find-my-way) resolves an absolute-form target to its path before matching, so the route handleris dispatched normally. Two places on the middleware side matched against the raw request target instead:
@fastify/middieengine atpackages/platform-fastify/adapters/middie/fastify-middie.ts.NestJS carried this fork to apply an earlier path-decoding fix and it did not track the upstream absolute-form fix
released in
@fastify/middie@9.3.4.FastifyAdapter's own re-check increateMiddlewareFactory(), which tests the middleware path regexp againstreq.originalUrl.Both normalized and percent-decoded the target, but neither resolved absolute-form to a path, so the router and the
middleware layer disagreed about which path was being requested.
A second, related defect contributed. Because the adapter always passes
routerOptions(to install the versionconstraint), Fastify did not reflect the deprecated top-level router options (
ignoreTrailingSlash,ignoreDuplicateSlashes,caseSensitive,useSemicolonDelimiter) ininitialConfig.routerOptions, which is whatthe middleware engine reads. Applications passing those options at the top level had middleware normalize paths
differently from the router, which widened the mismatch.
Proof of concept
supertestandlight-my-requestalways emit origin-form targets, so the request has to be written to the socket:Observed on an affected version:
protected data— the middleware did not run.Expected, and observed on a patched version:
blocked by auth middleware.Patches
Fixed in 12.0.2 and 11.2.4. Upgrading to 12.0.3 or 11.2.5 is recommended.
@fastify/middiefork was removed and the package now depends on@fastify/middie@9.3.4, whichresolves absolute-form targets before matching.
find-my-way.routerOptionsso the middleware engine and therouter normalize paths identically.
Workarounds
If you cannot upgrade, reject non-origin-form request targets before middleware runs. Register the hook on the
Fastify instance before the application is initialized, so that it runs ahead of the middleware engine's own
onRequesthook, and confirm with the request above that the rejection takes effect:Rejecting or normalizing absolute-form targets at a reverse proxy in front of the application is equally effective.
Credit
Reported by ZeroVuln Labs.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nestjs/nest (@nestjs/platform-fastify)
v12.0.2Compare Source
v12.0.2 (2026-09-14)
Bug fixes
platform-socket.io,platform-wsmicroservicescommonnormalizePath(@Asadshah7950)corestatusCodeas http errors (@Asadshah7950)platform-fastifyEnhancements
microservicesDependencies
platform-fastifyCommitters: 16
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.