All 4 CVE vulnerabilities found in @fastify/static, with AI-generated Chinese analysis, references, and POCs.
Vendor: @fastify/static
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-15074 | @fastify/static vulnerable to route guard bypass via path traversal CWE-22 | 7.5 | High | 2026-07-23 |
| CVE-2026-7120 | @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths CWE-180 | 5.3 | Medium | 2026-07-23 |
| CVE-2026-6410 | @fastify/static vulnerable to path traversal in directory listing CWE-22 | 5.3 | Medium | 2026-04-16 |
| CVE-2026-6414 | @fastify/static vulnerable to route guard bypass via encoded path separators CWE-177 | 5.9 | Medium | 2026-04-16 |
All 4 known CVE vulnerabilities affecting @fastify/static with full Chinese analysis, references, and POCs where available.