Known vulnerabilities in Fastify-reply-from

Vendor: fastify.io
Software CPE: cpe:2.3:a:fastify.io:fastify-reply-from:*:*:*:*:*:*:*:*
Total vulnerabilities: 5
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Fastify-reply-from Fastify-reply-from is affected by 5 known vulnerabilities: 2 high, 3 medium Critical High Medium Low

Vulnerabilities (5)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU138405 - Unintended Proxy or Intermediary ('Confused Deputy')
CVE-2026-16158
CWE-441 High
No
No
12.6.4 20.07.2026 SB2026072014
#VU138403 - Improper input validation
CVE-2026-33805
CWE-20 Medium
No
No
12.6.4 20.07.2026 SB2026072013
#VU119106 - Unintended Proxy or Intermediary ('Confused Deputy')
CVE-2025-66415
CWE-441 Medium
No
No
12.5.0 03.12.2025 SB2025120342
#VU85064 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-51701
CWE-444 Medium
No
No
9.6.0 08.01.2024 SB2024010821
#VU138404 - Improper Access Control
CVE-2021-21321
CWE-284 High
No
No
4.0.2 23.02.2021 SB2021022331
SB2021041399