PT-2026-33038 · Npm · @Fastify/Reply-From+1
Climba03003
+3
·
Published
2026-04-15
·
Updated
2026-06-01
·
CVE-2026-33805
CVSS v4.0
9.0
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
@fastify/reply-from versions prior to 12.6.2
@fastify/http-proxy versions prior to 11.4.4
Description
A logic flaw in the header processing pipeline of the Node.js Fastify framework allows unauthenticated remote attackers to bypass security controls. The issue occurs because the
rewriteRequestHeaders() function processes the client's Connection header after the proxy has added its own headers. This allows an attacker to retroactively strip headers added by the proxy for routing, access control, or security purposes by listing them in the Connection header value. This can lead to unauthorized modification of protected information or the bypass of proxy identification and authorization mechanisms.Recommendations
Upgrade @fastify/reply-from to version 12.6.2 or later.
Upgrade @fastify/http-proxy to version 11.4.4 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastify-Http-Proxy
@Fastify/Reply-From