# CVE-2026-76169

## Summary

- **CVE ID:** CVE-2026-76169
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-288
- **Published:** Sep 4, 2026
- **Last Modified:** Sep 4, 2026

## Description

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later.

## Affected Products

- fastify — fastify (4.0.0)
- fastify — fastify (5.12.2)

## References

- [CNA](https://github.com/fastify/fastify/security/advisories/GHSA-p68q-wchp-6fh7)
- [CNA](https://cna.openjsf.org/security-advisories.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.53%
- **EPSS Percentile:** 43.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._