fastify-reply-from affected by bypass of reply forwarding
Moderate severity
GitHub Reviewed
Published
Dec 1, 2025
in
fastify/fastify-reply-from
•
Updated Dec 2, 2025
Description
Published by the National Vulnerability Database
Dec 1, 2025
Published to the GitHub Advisory Database
Dec 2, 2025
Reviewed
Dec 2, 2025
Last updated
Dec 2, 2025
Summary
By crafting a malicious URL, an attacker could access routes that are not allowed, even though the
reply.fromis defined for specific routes in@fastify/reply-from.Details
An attacker can bypass the route defined by the
@fastify/reply-frompackage by adding a..symbol, which, forcurlversion8.7.1, is%2e%2e.Impact
Everyone is using this package with the routes option to protect a 3rd-party resource.
References