PT-2025-23220 · Fabio · Fabio

47Cid

·

Published

2025-05-29

·

Updated

2026-03-13

·

CVE-2025-48865

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Fabio versions prior to 1.6.6
Description Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. A vulnerability in how it processes hop-by-hop headers allows clients to remove X-Forwarded headers (except X-Forwarded-For). This creates potential security vulnerabilities as the receiving application should trust these headers. The attack relies on the behavior that headers can be defined as hop-by-hop via the HTTP Connection header. Some custom headers can be removed and, in certain cases, manipulated.
Recommendations For versions prior to 1.6.6, update to version 1.6.6 to resolve the issue. As a temporary workaround, consider restricting the ability of clients to remove or modify X-Forwarded headers until the update is applied. Avoid using the X-Forwarded-Host and X-Forwarded-Port headers in sensitive operations until the issue is resolved.

Exploit

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2025-48865
GHSA-Q7P4-7XJV-J3WF
GO-2025-3722
OPENSUSE-SU-2025:15225-1

Affected Products

Fabio