Skip to content

Security: Update @fastify/middie to fix CVE-2026-22031 #105

@melvincarvalho

Description

@melvincarvalho

Vulnerability

Package: @fastify/middie
CVE: CVE-2026-22031
Summary: Fastify Middie Middleware Path Bypass
Advisory: GHSA-cxrg-g7r8-w69p

Current State

JSS currently depends on @fastify/middie version <=9.0.3 which is vulnerable.

Fix

Update @fastify/middie to ^9.1.0 which contains the patch.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions