fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastify
Fastify reply-from |
|
| Vendors & Products |
Fastify
Fastify reply-from |
Mon, 01 Dec 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0. | |
| Title | fastify-reply-from bypass of reply forwarding | |
| Weaknesses | CWE-441 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-01T22:39:32.468Z
Updated: 2025-12-02T14:13:45.644Z
Reserved: 2025-11-28T23:33:56.366Z
Link: CVE-2025-66415
Updated: 2025-12-02T14:13:41.816Z
Status : Awaiting Analysis
Published: 2025-12-01T23:15:54.053
Modified: 2025-12-02T17:16:29.163
Link: CVE-2025-66415
No data.