Impact
The vulnerability resides in the @fastify/static plugin, which serves files from a configured root. In version strings older than 10.1.4, the route matcher is case-sensitive while the underlying filesystem on Windows or the default macOS volume is not. This mismatch allows an attacker to modify the letter case of a path segment that is protected by a route guard or an allowedPath rule. The altered path does not match the guard, and the request is forwarded to the static handler, which then resolves the path on disk and serves the protected file. The consequence is that an unauthenticated user can read a file that was intended to be shielded by application‑level authorization. This is a classic example of CWE‑178 (Improper Case Conversion) combined with CWE‑284 (Improper Authorization).
Affected Systems
Any deployment that uses @fastify/static prior to version 10.1.4 and runs on a case‑insensitive filesystem such as Windows or a default macOS volume is affected. The vulnerability applies whenever static files are served from a root directory that contains files or directories whose names have case variations that are guarded by route rules.
Risk and Exploitability
The CVSS v3.1 score of 5.3 classifies the issue as moderate severity. The EPSS score of less than 1% suggests that exploitation is unlikely in the current threat landscape, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Nonetheless, the attack vector is local to the web application: an unauthenticated HTTP request that alters case in a protected path can bypass authentication checks and read sensitive files. The attacker requires no elevated privileges beyond the ability to send requests to the target; the exploitation is completely remote through the HTTP interface.
OpenCVE Enrichment