CVE-2026-2293
NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13.
| CWE | CWE-863 |
| Vendor | nest.js |
| Product | nest.js |
| Published | Feb 27, 2026 |
| Last Updated | Feb 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for nest.js nest.js
Be the first to know when new unknown vulnerabilities affecting nest.js nest.js are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
nest.js / nest.js
11.1.13
References
Credits
Cristian Vargas