PatchSiren

@fastify/reply-from CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH @fastify/reply-from CVE published 2026-07-18

CVE-2026-16158

CVE-2026-16158 is a high-severity vulnerability in @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4. The vulnerability allows cross-upstream data access and modification due to improper URL cache key generation. The default configuration is affected, but setting disableCache to true prevents the behavior. A patch is available in version 12.6.4. This vulnerability has significant oper [truncated]

CRITICAL @fastify/reply-from CVE published 2026-04-15

CVE-2026-33805

CVE-2026-33805 is a critical vulnerability in Fastify's proxy packages where the client's Connection header is processed after proxy-added headers are applied via rewriteRequestHeaders. This ordering flaw allows attackers to retroactively strip headers added by the proxy for routing, access control, or security purposes by listing them in the Connection header value. The vulnerability affects @fastify/rep [truncated]