π¨ CVE-2026-7120
@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2.
π@cveNotify
@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by requesting equivalent non-canonical pathnames, causing files that were intended to be denied to be served anyway. The bypass does not allow access outside the configured static root by itself, it defeats path-based filtering only. The issue is patched in @fastify/static 10.1.2.
π@cveNotify
OpenJS Foundation CVE Numbering Authority
Security Advisories
The OpenJS Foundationβs CVE Numbering Authority (CNA)
π¨ CVE-2026-42980
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
π@cveNotify
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-42900
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
π@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
π@cveNotify
π¨ CVE-2026-42975
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
π@cveNotify
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
π@cveNotify
π¨ CVE-2026-48581
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
π@cveNotify
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-49165
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
π@cveNotify
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-49172
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
π@cveNotify
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-49784
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
π@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50293
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50333
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
π@cveNotify
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50342
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
π@cveNotify
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50351
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
π@cveNotify
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50356
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
π@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50522
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
π@cveNotify
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-54987
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-54989
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-55014
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
π@cveNotify
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50315
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
π@cveNotify
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50317
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
π@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50326
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-50335
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
π@cveNotify
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
π@cveNotify