PT-2026-108208 · Fastify · @Fastify/Reply-From
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
@fastify/reply-from versions prior to 12.7.0
Description
Built-in HTTPS transports in this Fastify plugin override the secure default by setting
rejectUnauthorized to false. This prevents the proxy from verifying the TLS certificate of the upstream server, even when configured for HTTPS. An on-path network attacker can impersonate the configured HTTPS upstream to read forwarded credentials and request bodies, or return forged responses that the application trusts.Recommendations
Update to version 12.7.0 or later.
As a temporary workaround, pass an explicit
rejectUnauthorized true on the transport, supply an already configured undici instance, or use the undici global agent.Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Fastify/Reply-From