CVE-2026-18248Patch(fastify / fastify\/aws-lambda)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch fastify fastify\/aws-lambda systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not stripped from the incoming event. An unauthenticated attacker who can set a single HTTP header can therefore forge the entire Lambda proxy event, including the authorizer context, and override the genuine one. This results in a full authentication and authorization bypass and privilege escalation for any application that trusts request.awsLambda.event for identity or access control. Only version 6.4.0 is affected. Patches: upgrade to @fastify/aws-lambda 6.4.1, which resolves the decoration only through the internal per-invocation token and strips the reserved headers before the request is processed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/aws-lambda

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-03); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
fastify\/aws-lambda

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-03: 2Mentions · 2026-08-04: 2Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-08-03: 2Technical Details · 2026-08-04: 208-0308-04
Signal classification3 categories
Patch
250.0%
General
125.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-032
General1Patch1
2026-08-042
Disclosure1Patch1
Full discourse4 posts
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-18248 @fastify/aws-lambda Client-controlled headers could let attackers forge API Gateway authorizer claims and bypass identity-based access controls Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-08-03/TIER_2_CVE-2026-18248.md #CyberSecurity #CloudSecurity #VulnerabilityManagement

    Post summary

    A new Fastify AWS Lambda vulnerability (CVE‑2026‑18248) is disclosed, where client‑controlled headers can forge authorizer claims to bypass identity checks; no PoC, exploit, patch, or active exploitation is referenced.

    00011275
    59 followersView on X
  • Sami Laiho@samilaiho
    Patch

    @fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18248 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1

    Post summary

    The tweet cites CVE-2026-18248 as a critical Lambda event spoofing flaw and confirms that an official fix is available.

    00001950
    30.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-18248 Authentication Bypass in @fastify/aws-lambda 6.4.0 via HTTP Header Injection https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-18248

    Post summary

    The snippet announces CVE‑2026‑18248, noting an authentication bypass via HTTP header injection, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000115
    4.1K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Critical-severity security fix in @fastify/aws-lambda@6.4.1 just released! Patches CVE-2026-18248: Lambda event spoofing via a client-controlled x-apigateway-event header (auth bypass). https://github.com/fastify/aws-lambda-fastify/security/advisories/GHSA-m93c-jj3f-68ph

    Post summary

    Fastify’s @aws-lambda library has issued a critical patch (v6.4.1) to fix CVE‑2026‑18248, a Lambda event spoofing vulnerability that can lead to auth bypass.

    00000239
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/aws-lambda6.4.0node.js-

Explore more