HTTPS Transport Flaw in Fastify Plugin from Fastify
CVE-2026-107318
7.4HIGH
What is CVE-2026-107318?
The @fastify/reply-from plugin, utilized for forwarding requests to upstream HTTP or HTTPS servers, has a vulnerability in versions prior to 12.7.0. This issue arises because built-in HTTPS transports lack proper TLS certificate verification by default, setting rejectUnauthorized to false. An attacker on the network can exploit this flaw, impersonating the upstream HTTPS server, capturing sensitive data such as credentials and request bodies, and sending forged responses that the application may trust. Users are advised to upgrade to version 12.7.0 or later, and can apply workarounds by enabling rejectUnauthorized or configuring an undici instance.
Affected Version(s)
@fastify/reply-from 0 < 12.7.0
@fastify/reply-from 12.7.0
