Please report security issues to support@nestjs.com.
Security: nestjs/nest
Security
SECURITY.md
-
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in @nestjs/coreGHSA-36xv-jgw5-4q75 published
Apr 3, 2026 by kamilmysliwiecModerate -
Fastify HEAD Request Middleware BypassGHSA-wf42-42fg-fg84 published
Mar 16, 2026 by kamilmysliwiecHigh -
Fastify URL Encoding Middleware BypassGHSA-r4wm-x892-vjmx published
Feb 28, 2026 by kamilmysliwiecHigh -
Fastify URL Encoding Middleware Bypass (TOCTOU)GHSA-8wpr-639p-ccrj published
Dec 29, 2025 by kamilmysliwiecHigh -
@nestjs/devtools-integration: CSRF to Sandbox Escape Allows for RCE against JS DevelopersGHSA-85cg-cmq5-qjm7 published
Aug 1, 2025 by kamilmysliwiecCritical
Learn more about advisories related to nestjs/nest in the GitHub Advisory Database