HTTPS Transport Flaw in Fastify Plugin from Fastify
CVE-2026-107318

7.4HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107318?

The @fastify/reply-from plugin, utilized for forwarding requests to upstream HTTP or HTTPS servers, has a vulnerability in versions prior to 12.7.0. This issue arises because built-in HTTPS transports lack proper TLS certificate verification by default, setting rejectUnauthorized to false. An attacker on the network can exploit this flaw, impersonating the upstream HTTPS server, capturing sensitive data such as credentials and request bodies, and sending forged responses that the application may trust. Users are advised to upgrade to version 12.7.0 or later, and can apply workarounds by enabling rejectUnauthorized or configuring an undici instance.

Affected Version(s)

@fastify/reply-from 0 < 12.7.0

@fastify/reply-from 12.7.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mcollina
UlisesGascon
oss-security-shopify
.