๐Ÿ” CVE Alert

CVE-2026-18248

CRITICAL 9.1

@fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not stripped from the incoming event. An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context, and override the genuine one. This results in a full authentication and authorization bypass and privilege escalation for any application that trusts request.awsLambda.event for identity or access control. Only version 6.4.0 is affected. Patches: upgrade to @fastify/aws-lambda 6.4.1, which resolves the decoration only through the internal per-invocation token and strips the reserved headers before the request is processed.

CWE CWE-345
Vendor @fastify/aws-lambda
Product @fastify/aws-lambda
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for @fastify/aws-lambda @fastify/aws-lambda

Be the first to know when new critical vulnerabilities affecting @fastify/aws-lambda @fastify/aws-lambda are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

@fastify/aws-lambda / @fastify/aws-lambda
6.4.0 < 6.4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fastify/aws-lambda-fastify/security/advisories/GHSA-m93c-jj3f-68ph cna.openjsf.org: https://cna.openjsf.org/security-advisories.html

Credits

๐Ÿ” EQSTLab adrai UlisesGascon mcollina useworld