Server-Side Request Forgery Vulnerability in Fastify Products from Fastify
CVE-2026-33805
9CRITICAL
What is CVE-2026-33805?
The vulnerability in Fastify affects versions prior to v12.6.2 of @fastify/reply-from and prior to v11.4.4 of @fastify/http-proxy. Attackers can exploit this weakness by manipulating the client's Connection header, allowing them to retroactively remove proxy-added headers that are critical for routing, access control, and security. This manipulation could compromise the integrity of upstream requests, making it vital for users to upgrade to the latest versions to maintain security.
Affected Version(s)
@fastify/http-proxy 0 < 11.4.4
@fastify/reply-from 0 < 12.6.2
@fastify/http-proxy 11.4.4
References
CVSS V4
Score:
9
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
FredKSchott
mcollina
UlisesGascon
climba03003
