CVE-2026-7120Fastify · Fastify-static
Vulnerability data via NVD (ingested)
@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-7120product:"Fastify Fastify-static"http.html:"Fastify-static"More intel sources (5)
vuln:CVE-2026-7120vulnerabilities.cve_id: CVE-2026-7120CVE-2026-7120CVE-2026-7120"CVE-2026-7120" exploit -site:nvd.nist.gov