216.73.217.22

CVE-2026-33805

· Published 15/04/2026 11:16 · Modified 15/04/2026 14:16

Labels: CVE-2026-33805 2026-04-15CVE-2026-33805CWE-644ce714d77-add3-4f53-aff5-83d477b104bb

Essential information

Published
15/04/2026 11:16
Modified
15/04/2026 14:16
Author
Creator
CVSS
9.0 CRITICAL (v3) 9.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection header value. Any header added by the proxy for routing, access control, or security purposes can be selectively removed by a client. @fastify/http-proxy is also affected as it delegates to @fastify/reply-from. Upgrade to @fastify/reply-from v12.6.2 or @fastify/http-proxy v11.4.4 or later.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ce714d77-add3-4f53-aff5-83d477b104bb
NVD
View on NVD

Affected products (CPE)

ProductCPE
fastify / reply-from cpe:2.3:a:fastify:reply-from:12.6.1:*:*:*:*:*:*:*
fastify / http-proxy cpe:2.3:a:fastify:http-proxy:11.4.3:*:*:*:*:*:*:*

References