
CVE-2026-18248 @fastify/aws-lambda Client-controlled headers could let attackers forge API Gateway authorizer claims and bypass identity-based access controls Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-08-03/TIER_2_CVE-2026-18248.md #CyberSecurity #CloudSecurity #VulnerabilityManagement
Post summary
A new Fastify AWS Lambda vulnerability (CVE‑2026‑18248) is disclosed, where client‑controlled headers can forge authorizer claims to bypass identity checks; no PoC, exploit, patch, or active exploitation is referenced.



