PatchSiren

@fastify/aws-lambda CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL @fastify/aws-lambda CVE published 2026-08-03

CVE-2026-18248

The @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context. In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token. An unauthenticated attacker who can set a single HTTP header ca [truncated]