CVE-2026-90982

CVE-2026-90982 published: @fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume, a route guard or allowedPath restriction can be bypassed ...

View full NVD advisory → ← Back to CVE watch