News

NestJS 12.1 is out: built-in cookies, CSRF protection and Fastify file uploads

On September 23, 2026 NestJS 12.1 was released: built-in adapter-agnostic cookies, CSRF protection and security headers, file uploads in Fastify and multiple global prefixes.

September 23, 2026
1 min read
NestJS 12.1 is out: built-in cookies, CSRF protection and Fastify file uploads

What's new

  • Cookies out of the box — the same for Express and Fastify, no adapter-specific packages.
  • CSRF protection and security headers built into the framework.
  • File uploads in Fastify — interceptors backed by @fastify/multipart.
  • Multiple global route prefixes, for example for different API versions.
  • Fixes: Redis client reconnects in microservices, middleware after transient providers, the ParseDatePipe default value.

What to watch out for

This is a minor release with no breaking changes — upgrade from 12.0 directly. If you already use third-party packages for CSRF protection or security headers, make sure the built-in protection doesn't duplicate them.

How to upgrade

  1. Update all @nestjs/* packages to the same version and check the migration guide.
  2. Check the Node.js version on servers and in CI.
  3. Run the API unit and e2e tests before rolling out.

We build and maintain NestJS and Node.js backends: we will upgrade the framework and dependencies, cover it with tests and roll out without downtime.

Source: official release announcement.

How we can help

-5%
Special Offer
Extra discount with promo code on any project
FIRST5
Get Discount

Related posts