GHSA-gwhp-pf74-vj37
CRITICALCVE-2026-33805@fastify/reply-from and @fastify/http-proxy process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers (like access control or identification headers) from upstream requests by listing them in the Connection header value. This affects applications using these plugins with custom header
- Affected
- <= 12.6.1
- Fixed in
- 12.6.2
- Weakness
- CWE-644
- Published
- 2026-04-16
- Source
- github