Impact
@fastify/auth is a Fastify plugin that combines multiple authentication and authorization strategies for route protection. In versions 5.0.0 through 5.1.0, using the “or” relation together with the run “all” option and a nested array that represents an AND group results in order‑dependent evaluation. The engine discards an earlier failing check and uses the outcome of the last check in the group. Consequently, a request that satisfies only the last member of an AND group, such as a user with a valid API key but not an administrator, is incorrectly authorized. This flaw allows attackers to obtain privileges they should not have, effectively bypassing configured authorization controls.
Affected Systems
The vulnerability affects the @fastify/auth plugin for Fastify, specifically versions 5.0.0 through 5.1.0. Users running those releases on any Fastify application that employs composite auth strategies are potentially exposed. Versions 5.1.1 and later contain the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating high severity. The EPSS score is below 1 %, implying a very low probability of widespread exploitation at this time, and the issue is not listed in the CISA KEV catalog. Exploitation requires sending crafted HTTP requests to routes protected by the affected auth composition; the attack is remote and does not require privileged local access. Organizations should treat the flaw as significant if they rely on fine‑grained authorization, especially when using nested AND groups with the “or” relation.
OpenCVE Enrichment