CVE Feed

    Dashboard / CVE / CVE-2026-33805

    CVE-2026-33805

    @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection header value. Any header added by the proxy for routing, access control, or security purposes can be selectively removed by a client. @fastify/http-proxy is also affected as it delegates to @fastify/reply-from. Upgrade to @fastify/reply-from v12.6.2 or @fastify/http-proxy v11.4.4 or later.

    Published:Apr 15, 2026
    Last Modified:Jun 1, 2026
    EPS:Apr 15, 2026
    EPSS Score:0.00019
    CVSS Score:8.6

    Affected Products

    Vendor
    Fastify
    Product
    Fastify-http-proxy
    Vendor
    Fastify
    Product
    Fastify-reply-from
    Vendor
    Fastify
    Product
    Fastify\/http-proxy
    Vendor
    Fastify
    Product
    Reply-from
    Vendor
    Fastify-reply-from Project
    Product
    Fastify-reply-from

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High