HOMEVULNERABILITIESCVE-2026-22031
HIGH

CVE-2026-22031

Published: January 19, 2026· Updated: Mar 13, 2026

8.4
CVSS v3.1

Official Description

@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 where middleware registered with a specific path prefix can be bypassed using URL-encoded characters (e.g., `/%61dmin` instead of `/admin`). While the middleware engine fails to match the encoded path and skips execution, the underlying Fastify router correctly decodes the path and matches the route handler, allowing attackers to access protected endpoints without the middleware constraints. Version 9.1.0 fixes the issue.

NVD Source

Technical Analysis

CVE-2026-22031 requires local access, meaning attackers must already have a foothold on the target system.

Exploitation requires some privileges, which limits the exposure to scenarios where an attacker has already gained initial access.

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Quick Facts

CVE IDCVE-2026-22031
CVSS Score8.4 / 10
SeverityHIGH
CISA KEVNo
PublishedJan 19, 2026

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-22031 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWATCH.COM. CVE data is provided under the NVD usage policy.