CVE-2026-7120 | fastify fastify-static up to 10.1.1 Path Normalization allowedPath path traversal (EUVD-2026-47870)
A vulnerability classified as problematic was found in fastify fastify-static up to 10.1.1. The impacted element is the function allowedPath of the component Path Normalization. Such manipulation of the argument allowedPath leads to path traversal.
This vulnerability is documented as CVE-2026-7120. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More