CVE-2026-2293
NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13.
| CWE | CWE-863 |
| Vendor | nest.js |
| Product | nest.js |
| Published | Feb 27, 2026 |
| Last Updated | Jul 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for nest.js nest.js
Be the first to know when new high vulnerabilities affecting nest.js nest.js are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
nest.js / nest.js
11.1.13
References
fluidattacks.com: https://fluidattacks.com/advisories/neton github.com: https://github.com/nestjs/nest/ github.com: https://github.com/nestjs/nest/releases/tag/v11.1.14 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-2293 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2443367 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2293.json
Credits
Cristian Vargas