Ulises Gascón@kom_256Patch
The tweet announces a critical patch for CVE-2026-33805 in two Fastify packages, providing official advisories and version information, but no exploit or PoC details.
cvereports@_cvereportsDisclosure
The post announces CVE‑2026‑33805, a header‑abuse flaw in @fastify/reply‑from and @fastify/http‑proxy allowing unauthenticated remote attackers to bypass access control, without providing PoC, exploit code, or patch details.
Infoflowcloud@infoflowcloudDisclosure
A new CVE-2026-33805 has been disclosed, affecting specific Fastify packages due to a header processing flaw, but no PoC, exploit, active exploitation, or patch info is provided.
CVE@CVEnewDisclosure
CVE-2026-33805 affects @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier, where the client’s Connection header is processed after the proxy adds its own headers. The note provides affected versions and a brief description of the issue but no PoC, exploit, or patch details.
PulsePatch.io@pulsepatchioDisclosure
The post announces a newly disclosed CVE affecting Fastify, details the header abuse vulnerability, but offers no PoC, exploit, or patch information.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The tweet serves as a brief advisory about a header stripping vulnerability in fastify reply-from, but does not provide details on exploitation, patches, or PoC.
0day Signal@0dayPublishingDisclosure
CVE-2026-33805 has been disclosed as a Fastify proxy bypass that enables attackers to strip authentication headers via crafted Connection headers.