CVE-2026-107318 — @fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server.
Description
@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the proxy does not verify the TLS certificate of the upstream even when the application points it at an https upstream in the default configuration. An on-path network attacker can therefore impersonate the configured HTTPS upstream, read the credentials and request bodies the proxy forwards, and return forged responses that the application trusts. The issue is fixed in @fastify/reply-from 12.7.0, and users should upgrade to 12.7.0 or later. As a workaround, pass an explicit rejectUnauthorized true on the transport, supply an already configured undici instance, or use the undici global agent.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
High
Integrity
A
None
Availability
References
Related threats
same CWE or vendorCVE-2026-96207 — Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-96207 · 3h ago
CVE-2026-84032 — IBM Guardium Data Protection 12.2.2 could allow a remote attacker to conduct a man-in-the-middle attack due to improper certificate validation.
CVE-2026-84032 · 4h ago
CVE-2026-95210 — Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
CVE-2026-95210 · 8h ago
CVE-2026-95208 — An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service …
CVE-2026-95208 · 10h ago
CVE-2026-107587 — Improper certificate validation in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to hav…
CVE-2026-107587 · 14h ago
CVE-2026-87425 — An unauthenticated remote attacker can modify the TLS client trust store in Brocade ASCG versions before 3.5.0.
CVE-2026-87425 · 19h ago