PT-2026-108208 · Fastify · @Fastify/Reply-From

·

CVE-2026-107318

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @fastify/reply-from versions prior to 12.7.0
Description Built-in HTTPS transports in this Fastify plugin override the secure default by setting rejectUnauthorized to false. This prevents the proxy from verifying the TLS certificate of the upstream server, even when configured for HTTPS. An on-path network attacker can impersonate the configured HTTPS upstream to read forwarded credentials and request bodies, or return forged responses that the application trusts.
Recommendations Update to version 12.7.0 or later. As a temporary workaround, pass an explicit rejectUnauthorized true on the transport, supply an already configured undici instance, or use the undici global agent.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107318

Affected Products

@Fastify/Reply-From