CVE-2026-16158 is a high-severity vulnerability in @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4. The vulnerability allows cross-upstream data access and modification due to improper URL cache key generation. The default configuration is affected, but setting disableCache to true prevents the behavior. A patch is available in version 12.6.4. This vulnerability has significant oper [truncated]
CRITICAL@fastify/reply-fromCVE published 2026-04-15
CVE-2026-33805 is a critical vulnerability in Fastify's proxy packages where the client's Connection header is processed after proxy-added headers are applied via rewriteRequestHeaders. This ordering flaw allows attackers to retroactively strip headers added by the proxy for routing, access control, or security purposes by listing them in the Connection header value. The vulnerability affects @fastify/rep [truncated]