🔓 VULNERABILITIES & CVEs
-
Fastify Static Vulnerable to Route Guard Bypass via Path Traversal — CVE-2026-15074
Fastify static module allows attackers to bypass route guards by exploiting path traversal vulnerabilities.- This can lead to unauthorized access to protected resources.
-
Fastify Static Vulnerable to Authorization Bypass via Non-Canonical URL Path — CVE-2026-7120
Authorization can be bypassed in Fastify static by using non-canonical URL paths, enabling unauthorized access.- Attackers may exploit URL normalization weaknesses.
-
RecordThe Alertmanager Templates Test Endpoint Vulnerable — CVE-2026-21723, CVSS 5.3
The alertmanager templates test endpoint (/api/alertmanager/templates/test) in RecordThe has a security vulnerability.- Details on impact and exploitation are limited at this time.