Input validation error in Fastify-http-proxy and Fastify-reply-from - CVE-2026-33805
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to strip proxy-added headers.
The vulnerability exists due to improper input validation in the connection header handling logic of @fastify/reply-from and @fastify/http-proxy when processing requests containing a crafted Connection header. A remote attacker can send a specially crafted request to strip proxy-added headers.
Affected software
Fastify-reply-from
How to mitigate CVE-2026-33805
Fastify-reply-from - update to 12.6.4