Vulnerabilities
Vulnerable Software
Fastify:  >> Reply-From  >> 0.4.0  Security Vulnerabilities
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.
CVSS Score
5.4
EPSS Score
0.001
Published
2025-12-01
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with `@fastify/reply-from` could misinterpret the incoming body by passing an header `ContentType: application/json ; charset=utf-8`. This can lead to bypass of security checks. This vulnerability has been patched in '@fastify/reply-from` version 9.6.0.
CVSS Score
5.3
EPSS Score
0.002
Published
2024-01-08


Contact Us

Shodan ® - All rights reserved