PT-2025-23220 · Fabio · Fabio

·

CVE-2025-48865

·

Published

2025-05-29

·

Updated

2026-03-13

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Fabio versions prior to 1.6.6
Description Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. A vulnerability in how it processes hop-by-hop headers allows clients to remove X-Forwarded headers (except X-Forwarded-For). This creates potential security vulnerabilities as the receiving application should trust these headers. The attack relies on the behavior that headers can be defined as hop-by-hop via the HTTP Connection header. Some custom headers can be removed and, in certain cases, manipulated.
Recommendations For versions prior to 1.6.6, update to version 1.6.6 to resolve the issue. As a temporary workaround, consider restricting the ability of clients to remove or modify X-Forwarded headers until the update is applied. Avoid using the X-Forwarded-Host and X-Forwarded-Port headers in sensitive operations until the issue is resolved.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48865
GHSA-Q7P4-7XJV-J3WF
GO-2025-3722
OPENSUSE-SU-2025:15225-1

Affected Products

Fabio