๐Ÿ” CVE Alert

CVE-2026-107318

HIGH 7.4

@fastify/reply-from vulnerable to improper certificate validation in built-in HTTPS transports

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the proxy does not verify the TLS certificate of the upstream even when the application points it at an https upstream in the default configuration. An on-path network attacker can therefore impersonate the configured HTTPS upstream, read the credentials and request bodies the proxy forwards, and return forged responses that the application trusts. The issue is fixed in @fastify/reply-from 12.7.0, and users should upgrade to 12.7.0 or later. As a workaround, pass an explicit rejectUnauthorized true on the transport, supply an already configured undici instance, or use the undici global agent.

CWE CWE-295
Vendor @fastify/reply-from
Product @fastify/reply-from
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for @fastify/reply-from @fastify/reply-from

Be the first to know when new high vulnerabilities affecting @fastify/reply-from @fastify/reply-from are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

@fastify/reply-from / @fastify/reply-from
0 < 12.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-j425-jw94-m29r cna.openjsf.org: https://cna.openjsf.org/security-advisories.html

Credits

mcollina UlisesGascon ๐Ÿ” oss-security-shopify