A vulnerability classified as problematic was found in fastify fastify-static up to 10.1.1. The impacted element is the function
allowedPath of the component Path Normalization. Such manipulation of the argument allowedPath leads to path traversal.
This vulnerability is documented as CVE-2026-7120. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.