CVE-2025-48865Disclosure(fabiolb / fabio)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for fabiolb fabio systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except X-Forwarded-For) due to a vulnerability in how it processes hop-by-hop headers. Fabio adds HTTP headers like X-Forwarded-Host and X-Forwarded-Port when routing requests to backend applications. Since the receiving application should trust these headers, allowing HTTP clients to remove or modify them creates potential security vulnerabilities. Some of these custom headers can be removed and, in certain cases, manipulated. The attack relies on the behavior that headers can be defined as hop-by-hop via the HTTP Connection header. This issue has been patched in version 1.6.6.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-348

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fabio

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
fabio

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-11: 1Mentions · 2026-03-12: 2Mentions · 2026-03-13: 1PoC Mentioned / Linked · 2026-03-12: 1Active Exploitation · 2026-03-13: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 103-1103-1203-13
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-122
Disclosure2
2026-03-131
Active Exploitation1
Full discourse4 posts
  • Praetorian@praetorianlabs
    Disclosure

    Two new CVEs. Two different proxies. One systemic flaw. CVE-2025-48865 (Fabio): Abuse the Connection header → strip X-Forwarded-For → backend's access control never triggers. CVE-2025-64484 (OAuth2-proxy): Send X_Forwarded_Email (underscore) → proxy misses it → Django/Flask normalize it → full auth bypass. Your proxy isn't a trust boundary. It's an attack surface. Full breakdown in the replies ↓ #AppSec #CVE #OffensiveSecurity

    Post summary

    The post announces two new CVEs for Fabio and OAuth2‑proxy, explaining that header manipulation can bypass backend access controls, with no mention of active attacks, patches, or exploit tools.

    3301451.4K
    8.5K followersView on X
  • Praetorian@praetorianlabs
    Disclosure

    Two new CVEs. Two different proxies. One systemic flaw. 🔥CVE-2025-48865 (Fabio): Abuse the Connection header → strip X-Forwarded-For → backend's access control never triggers. 🔥CVE-2025-64484 (OAuth2-proxy): Send X_Forwarded_Email (underscore) → proxy misses it → Django/Flask normalize it → full auth bypass. Your proxy isn't a trust boundary. It's an attack surface. Full breakdown 🔗 https://buff.ly/yg75n4T #AppSec #CVE #OffensiveSecurity

    Post summary

    The tweet announces two new CVEs affecting proxy software, detailing header abuse that leads to access control bypasses, and points to a link for a deeper technical breakdown.

    010861.0K
    8.6K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting reverse proxy header manipulation vulnerabilities to bypass authentication and escalate privileges. CVE-2025-48865 (Fabio) and CVE-2025-64484 (OAuth2-Proxy) enable injection of crafted headers, leading to lateral movement within compromised networks. Runtime segmentation helps limit blast radius of such post-compromise activity. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/fabio-oauth2-proxy-2025-reverse-proxy-vulnerabilities

    Post summary

    The post reports that attackers are actively exploiting reverse proxy header manipulation CVEs CVE-2025-48865 and CVE-2025-64484 for privilege escalation and lateral movement within compromised networks.

    00000166
    1.9K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    CVE-2025-48865 and CVE-2025-64484 expose how HTTP header manipulation between reverse proxies and backend applications can enable authentication bypass and privilege escalation by exploiting hop-by-hop header stripping and header normalization inconsistencies. https://www.praetorian.com/blog/reverse-proxy-header-attacks/

    Post summary

    The post discloses how CVE-2025-48865 and CVE-2025-64484 allow authentication bypass and privilege escalation via inconsistent HTTP header handling between reverse proxies and backends.

    00000142
    242 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfabiolbfabio-go-

Explore more