CRITICAL
@fastify/aws-lambda
CVE published 2026-08-03
CVE-2026-18248
The @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context. In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token. An unauthenticated attacker who can set a single HTTP header ca [truncated]