Executive Summary
CVE-2026-106016 is a high-severity vulnerability affecting the File Handling component of the @fastify/static module in the Node.js ecosystem. This vulnerability enables attackers to bypass previously implemented mitigations for path traversal, specifically allowing unauthorized file disclosure within the static root of affected applications. The flaw is a bypass of an earlier fix (CVE-2026-6414) and has been actively discussed in the security community, with exploitation demonstrated by security researchers and bug bounty hunters. As of this report, CISA has not confirmed active exploitation in its Known Exploited Vulnerabilities catalog, but public advisories and technical discussions confirm that exploitation is possible and has occurred in the wild.
Technical Information
CVE-2026-106016 is a mitigation bypass vulnerability in the File Handling component of @fastify/static up to and including version 10.1.0. The vulnerability arises because the module fails to reject dot-dot (..) path segments in request pathnames before the file-resolution stage. This oversight allows attackers to craft HTTP requests with non-canonical pathnames, such as /static/../secret.txt, to bypass route-scoped middleware and access files within the static root that should be protected.
The root cause is the order of normalization and filtering: the underlying send library normalizes dot segments before applying its own path-traversal guard, which means that malicious path segments can evade middleware checks. The vulnerability does not allow access outside the configured static root by itself, but it does defeat route-guard filtering, exposing files that should be protected.
The issue is patched in @fastify/static version 10.1.1, which properly rejects non-canonical pathnames containing dot-dot segments before file resolution.
The technical impact includes unauthorized disclosure of sensitive files, potential exposure of credentials or configuration data, and the circumvention of intended access controls. The vulnerability is classified as High with a CVSS score of 7.5.
Exploitation in the Wild
Exploitation of CVE-2026-106016 has been demonstrated by security researchers and bug bounty hunters. Attackers, including unauthenticated remote actors, can exploit the vulnerability by sending HTTP requests with crafted pathnames containing .. segments. These requests can bypass middleware intended to restrict access to certain files, resulting in unauthorized file reads within the static root.
There are no public reports of exploitation by advanced persistent threat (APT) groups or widespread campaigns, but the simplicity of the attack vector makes it attractive for opportunistic attackers. Public advisories, GitHub issue trackers, and technical write-ups describe the exploitation method in detail, and proof-of-concept examples are available in the open-source community.
APT Groups using this vulnerability
As of the time of writing, there is no public attribution of CVE-2026-106016 to any specific APT group. No sector or country targeting information is available, and no results were found in MITRE or open-source threat actor databases for APT groups leveraging this vulnerability. The exploit is generic and could be used by any unauthenticated remote attacker.
Affected Product Versions
The affected product is @fastify/static in the Node.js ecosystem. All versions up to and including 10.1.0 are vulnerable. The issue is patched in version 10.1.1 and later. Organizations using @fastify/static version 10.1.0 or earlier are at risk and should upgrade immediately.
Workaround and Mitigation
The primary mitigation is to upgrade @fastify/static to version 10.1.1 or later, which addresses the vulnerability by properly rejecting non-canonical pathnames containing dot-dot segments. In addition to upgrading, organizations should audit access logs for suspicious requests containing ../ or other path traversal patterns, monitor for unusual file access patterns within the static root, and set up alerts for unexpected file reads or downloads from URLs that should be guarded by middleware. After patching, it is essential to verify that route-scoped middleware and file access controls are enforced as expected.
Indicators of Compromise
The following caveat applies: Indicators of compromise are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.
References
- NVD - CVE-2026-106016
- @fastify/static 10.1.1 Release Notes
- GitHub Security Advisories for @fastify/static
- MITRE ATT&CK T1086
- MITRE ATT&CK T1040
Rescana is here for you
Rescana provides a comprehensive Third-Party Risk Management (TPRM) platform, empowering organizations to continuously monitor, assess, and manage cyber risk across their supply chain. Our platform leverages advanced automation and threat intelligence to help you stay ahead of emerging vulnerabilities and regulatory requirements. We are happy to answer any questions at info@rescana.com.



