← Back to CVEs
CVE-2026-33805
N/ADescription
@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection header value. Any header added by the proxy for routing, access control, or security purposes can be selectively removed by a client. @fastify/http-proxy is also affected as it delegates to @fastify/reply-from. Upgrade to @fastify/reply-from v12.6.2 or @fastify/http-proxy v11.4.4 or later.
CVE Details
CVSS v3.1 ScoreN/A
Published4/15/2026
Last Modified4/17/2026
Sourcenvd
Honeypot Sightings0
Weaknesses (CWE)
CWE-644
References
https://cna.openjsf.org/security-advisories.html(ce714d77-add3-4f53-aff5-83d477b104bb)
https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-gwhp-pf74-vj37(ce714d77-add3-4f53-aff5-83d477b104bb)
https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-gwhp-pf74-vj37(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.