CVEFinder.io

CVE-2021-22963

🔶 medium
🔍 Scan for this CVE
Summary

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.

CVSS Score
6.1
Medium
EPSS Score
0.2
Exploit Probability
Published Date
2021-10-14
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 38.4% of all 340,405 vulnerabilities in our database.

#209,770
Below average severity
Severity Percentile
Last Modified 2024-11-21
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 1

https://hackerone.com/reports/1354255
Exploit Issue Tracking Third Party Advisory

🔗 Related CVEs 3

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-15074 ⚠️ high 7.5 0.5 @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the... 2026-07-23
CVE-2026-7120 🔶 medium 5.3 0.2 @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the ... 2026-07-23
CVE-2021-22964 ⚠️ high 8.8 0.4 A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect... 2021-10-14
These CVEs affect the same products