{"type":"bundle","id":"bundle--0e6e035e-3504-5109-86ec-62b4bc1f42e0","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--45cffc1a-b787-5e8e-a2cb-b710d4ad80be","created":"2026-09-20T20:04:10.899Z","modified":"2026-09-20T20:04:10.899Z","name":"Fastify malformed URLs can skip not-found auth","description":"Fastify before 5.12.2 can let malformed URLs reach encapsulated not-found handlers and skip intended authentication. Upgrade to 5.12.2.","aliases":["CVE-2026-76169","fastify malformed URL auth bypass"],"first_seen":"2026-09-04T00:00:00.000Z","last_seen":"2026-09-04T12:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"GitHub Security Advisory GHSA-p68q-wchp-6fh7","url":"https://github.com/fastify/fastify/security/advisories/GHSA-p68q-wchp-6fh7"},{"source_name":"NVD CVE-2026-76169","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76169"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-76169-fastify-malformed-url-not-found-auth-bypass"}]}]}