{"type":"bundle","id":"bundle--78331f66-3ea8-513a-907b-aa120816b6a2","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--b5fe2a9d-bd87-5990-a29b-d80e4b7d336e","created":"2026-09-20T19:03:30.901Z","modified":"2026-09-20T19:03:30.901Z","name":"@fastify/jwt key override authorization bypass","description":"@fastify/jwt is affected by a key-override authorization bypass. Upgrade to the patched release.","aliases":["CVE-2026-18500"],"first_seen":"2026-08-15T00:00:00.000Z","last_seen":"2026-08-15T12:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"NVD CVE-2026-18500","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18500"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-18500-fastify-jwt-key-override-auth-bypass"},{"source_name":"CVE Record CVE-2026-18500","url":"https://www.cve.org/CVERecord?id=CVE-2026-18500"}]}]}