AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-22963

MEDIUM · CVSS 6.1 EPSS 1.13%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-10-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-22963
Severity
MEDIUM
CVSS
6.1
EPSS
1.13%

Original NVD Description

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.