CVE-2026-16732Patch(fastify / fastify)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch fastify fastify systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host, protocol, hostname, ip, and ips values, checking the connecting address. That guard closes the IP, CIDR, and custom-function forms of trustProxy correctly, because those forms compile to predicates that inspect the connecting address. The hop-count form, where trustProxy is set to a number, compiles to a predicate that structurally ignores the address, so the guard is always satisfied for any hop count of one or more. Applications configured with a numeric trustProxy value, such as trustProxy set to 1 for a single reverse proxy, remain vulnerable: an attacker who can reach the Fastify origin directly, bypassing the front-facing proxy, can spoof the forwarded request fields exactly as in the unpatched version. The impact class matches the parent CVE-2026-3635, including host injection in generated URLs, HTTPS-enforcement bypass, secure-cookie and CSRF-origin bypass, and host-based routing and cache poisoning. Affected versions are fastify from 5.8.3 up to but not including 5.12.1. Patches: patched in fastify 5.12.1, where the numeric form of trustProxy is disabled at runtime and removed from the TypeScript type union. Workarounds: migrate to an IP, CIDR, or custom-function trustProxy value that validates the connecting address, and ensure the Fastify origin is only reachable through the trusted proxy chain.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-348

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Exploit: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
fastify

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-18: 1Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-19: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-18: 108-1808-19
Signal classification2 categories
Patch
150.0%
Exploit
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-181
Patch1
2026-08-191
Exploit1
Full discourse2 posts
  • ExploitGrid@exploitgrid
    Exploit

    Top CVEs w/ public exploits (Aug 19): CVE-2026-19500 SureForms contains an uncontrolled resource con... CVE-2026-16732 fastify vulnerable to X-Forwarded-* spoofing un... CVE-2026-18504 fastify vulnerable to schema validation bypass ... Protect via https://exploitgrid.net

    Post summary

    The post highlights several CVEs with publicly known exploits but lacks detailed technical info or patch guidance, implying that exploit code exists but is not elaborated upon.

    0100049
    35 followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in fastify@5.12.1 just released! Patches CVE-2026-16732. fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count. https://github.com/fastify/fastify/security/advisories/GHSA-3m5p-2c4r-xxw2

    Post summary

    Fastify version 5.12.1 released a security fix for CVE‑2026‑16732, addressing an X‑Forwarded‑* header spoofing flaw triggered through trustProxy hop‑count.

    00000220
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify-node.js-

Explore more