Known vulnerabilities in Fastify-reply-from 12.6.1
Vendor:
fastify.io
Software:
Fastify-reply-from
Version:
12.6.1
Software CPE:
cpe:2.3:a:fastify.io:fastify-reply-from:*:*:*:*:*:*:*:*
Website:
https://www.fastify.io/
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Vulnerabilities by Severity
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU138405 - Unintended Proxy or Intermediary ('Confused Deputy') CVE-2026-16158 |
CWE-441 | High | 12.6.4 | 20.07.2026 |
SB2026072014 |
||
| #VU138403 - Improper input validation CVE-2026-33805 |
CWE-20 | Medium | 12.6.4 | 20.07.2026 |
SB2026072013 |