This issue affects nest.Js: 11.1.13.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r4wm-x892-vjmx | Nest has a Fastify URL Encoding Middleware Bypass |
Tue, 14 Apr 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nestjs
Nestjs nest |
|
| CPEs | cpe:2.3:a:nestjs:nest:11.1.13:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Nestjs
Nestjs nest |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 03 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-551 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 27 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13. | |
| Title | NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass | |
| First Time appeared |
Nest.js
Nest.js nest.js |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:nest.js:nest.js:11.1.13:*:ios:*:*:*:*:* cpe:2.3:a:nest.js:nest.js:11.1.13:*:macos:*:*:*:*:* cpe:2.3:a:nest.js:nest.js:11.1.13:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Nest.js
Nest.js nest.js |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-02-27T17:07:59.779Z
Reserved: 2026-02-10T15:48:58.721Z
Link: CVE-2026-2293
Updated: 2026-02-27T17:07:48.467Z
Status : Analyzed
Published: 2026-02-27T17:16:33.357
Modified: 2026-04-14T00:30:36.907
Link: CVE-2026-2293
OpenCVE Enrichment
Updated: 2026-04-18T10:15:25Z
Github GHSA