Title: Security: Update @fastify/middie to fix CVE-2026-22031 · Issue #105 · JavaScriptSolidServer/JavaScriptSolidServer · GitHub
Open Graph Title: Security: Update @fastify/middie to fix CVE-2026-22031 · Issue #105 · JavaScriptSolidServer/JavaScriptSolidServer
X Title: Security: Update @fastify/middie to fix CVE-2026-22031 · Issue #105 · JavaScriptSolidServer/JavaScriptSolidServer
Description: Vulnerability Package: @fastify/middie CVE: CVE-2026-22031 Summary: Fastify Middie Middleware Path Bypass Advisory: GHSA-cxrg-g7r8-w69p Current State JSS currently depends on @fastify/middie version <=9.0.3 which is vulnerable. Fix Updat...
Open Graph Description: Vulnerability Package: @fastify/middie CVE: CVE-2026-22031 Summary: Fastify Middie Middleware Path Bypass Advisory: GHSA-cxrg-g7r8-w69p Current State JSS currently depends on @fastify/middie versio...
X Description: Vulnerability Package: @fastify/middie CVE: CVE-2026-22031 Summary: Fastify Middie Middleware Path Bypass Advisory: GHSA-cxrg-g7r8-w69p Current State JSS currently depends on @fastify/middie versio...
Opengraph URL: https://github.com/JavaScriptSolidServer/JavaScriptSolidServer/issues/105
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Security: Update @fastify/middie to fix CVE-2026-22031","articleBody":"## Vulnerability\n\n**Package:** `@fastify/middie` \n**CVE:** CVE-2026-22031 \n**Summary:** Fastify Middie Middleware Path Bypass \n**Advisory:** https://github.com/advisories/GHSA-cxrg-g7r8-w69p\n\n## Current State\n\nJSS currently depends on `@fastify/middie` version \u003c=9.0.3 which is vulnerable.\n\n## Fix\n\nUpdate `@fastify/middie` to `^9.1.0` which contains the patch.","author":{"url":"https://github.com/melvincarvalho","@type":"Person","name":"melvincarvalho"},"datePublished":"2026-01-21T08:35:23.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":0},"url":"https://github.com/105/JavaScriptSolidServer/issues/105"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:1afb0efb-6662-94ed-dda3-bc519aadb82d |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | B4D4:25A502:4627C7:600A01:69774E16 |
| html-safe-nonce | 20e756e43d25bc3815a678bcb6fc6ca99ab21c43123928b1bce915a14d148355 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJCNEQ0OjI1QTUwMjo0NjI3Qzc6NjAwQTAxOjY5Nzc0RTE2IiwidmlzaXRvcl9pZCI6IjkxNDU5NjAyNjk2MzU2MDM5OTAiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | c3d510ee51be4977d6e2cac64837ab3ee20046db23c2e726943576904f46c21e |
| hovercard-subject-tag | issue:3837167869 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/JavaScriptSolidServer/JavaScriptSolidServer/105/issue_layout |
| twitter:image | https://opengraph.githubassets.com/68137ebcaa125da1dbb451dec205c280de835ceea99e78465949ae35e8ff1fe8/JavaScriptSolidServer/JavaScriptSolidServer/issues/105 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/68137ebcaa125da1dbb451dec205c280de835ceea99e78465949ae35e8ff1fe8/JavaScriptSolidServer/JavaScriptSolidServer/issues/105 |
| og:image:alt | Vulnerability Package: @fastify/middie CVE: CVE-2026-22031 Summary: Fastify Middie Middleware Path Bypass Advisory: GHSA-cxrg-g7r8-w69p Current State JSS currently depends on @fastify/middie versio... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | melvincarvalho |
| hostname | github.com |
| expected-hostname | github.com |
| None | 3310064f35a62c06a4024ba37f41c06836f39376a095c2dfd2c4b693c34965be |
| turbo-cache-control | no-preview |
| go-import | github.com/JavaScriptSolidServer/JavaScriptSolidServer git https://github.com/JavaScriptSolidServer/JavaScriptSolidServer.git |
| octolytics-dimension-user_id | 205442424 |
| octolytics-dimension-user_login | JavaScriptSolidServer |
| octolytics-dimension-repository_id | 958025407 |
| octolytics-dimension-repository_nwo | JavaScriptSolidServer/JavaScriptSolidServer |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 958025407 |
| octolytics-dimension-repository_network_root_nwo | JavaScriptSolidServer/JavaScriptSolidServer |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 67d5f8d1d53c3cc4f49fc3bb8029933c3dc219e6 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width