PT-2026-33038 · Npm · @Fastify/Reply-From+1

Climba03003

+3

·

Published

2026-04-15

·

Updated

2026-06-01

·

CVE-2026-33805

CVSS v4.0

9.0

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions @fastify/reply-from versions prior to 12.6.2 @fastify/http-proxy versions prior to 11.4.4
Description A logic flaw in the header processing pipeline of the Node.js Fastify framework allows unauthenticated remote attackers to bypass security controls. The issue occurs because the rewriteRequestHeaders() function processes the client's Connection header after the proxy has added its own headers. This allows an attacker to retroactively strip headers added by the proxy for routing, access control, or security purposes by listing them in the Connection header value. This can lead to unauthorized modification of protected information or the bypass of proxy identification and authorization mechanisms.
Recommendations Upgrade @fastify/reply-from to version 12.6.2 or later. Upgrade @fastify/http-proxy to version 11.4.4 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05632
CVE-2026-33805
GHSA-GWHP-PF74-VJ37

Affected Products

Fastify-Http-Proxy
@Fastify/Reply-From