CVE-2026-33805Disclosure(fastify / fastify\/http-proxy)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fastify fastify\/http-proxy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection header value. Any header added by the proxy for routing, access control, or security purposes can be selectively removed by a client. @fastify/http-proxy is also affected as it delegates to @fastify/reply-from. Upgrade to @fastify/reply-from v12.6.2 or @fastify/http-proxy v11.4.4 or later.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-644CWE-444

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify\/http-proxy
  • reply-from

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-15); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
fastify\/http-proxyreply-from

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-04-15: 3Mentions · 2026-04-16: 3Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-15: 3Technical Details · 2026-04-16: 3Technical Details · 2026-04-28: 104-1504-1604-28
Signal classification3 categories
Disclosure
571.4%
General
114.3%
Patch
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-153
Disclosure1General1Patch1
2026-04-163
Disclosure3
2026-04-281
Disclosure1
Full discourse7 posts
  • Ulises Gascón@kom_256
    Patch

    🚨 Critical-severity security fix in @fastify/reply-from@12.6.2 and @fastify/http-proxy@11.4.4 just released! Patches CVE-2026-33805 — connection header abuse enables stripping of proxy-added headers https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-gwhp-pf74-vj37

    Post summary

    The tweet announces a critical patch for CVE-2026-33805 in two Fastify packages, providing official advisories and version information, but no exploit or PoC details.

    00001129
    5.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-33805: CVE-2026-33805: Connection Header Abuse in @fastify/reply-from and @fastify/http-proxy A logic flaw in the header processing pipeline of @fastify/reply-from and @fastify/http-proxy allows unauthenticated remote attackers to bypass acce... https://cvereports.com/reports/CVE-2026-33805

    Post summary

    The post announces CVE‑2026‑33805, a header‑abuse flaw in @fastify/reply‑from and @fastify/http‑proxy allowing unauthenticated remote attackers to bypass access control, without providing PoC, exploit code, or patch details.

    0000020
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33805 @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers v… https://www.cve.org/CVERecord?id=CVE-2026-33805 ----- Traducción: CVE-2026-33805 las… http://infoflow.cloud`

    Post summary

    A new CVE-2026-33805 has been disclosed, affecting specific Fastify packages due to a header processing flaw, but no PoC, exploit, active exploitation, or patch info is provided.

    0000030
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33805 @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers v… https://www.cve.org/CVERecord?id=CVE-2026-33805

    Post summary

    CVE-2026-33805 affects @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier, where the client’s Connection header is processed after the proxy adds its own headers. The note provides affected versions and a brief description of the issue but no PoC, exploit, or patch details.

    00000161
    57.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Fastify` applications are vulnerable to CVE-2026-33805, allowing attackers to strip proxy-added headers via `Connection` header abuse. This can lead to security control bypasses. #Fastify #WebSecurity #CVE https://www.pulsepatch.io/posts/cve-2026-33805-fastify-header-abuse

    Post summary

    The post announces a newly disclosed CVE affecting Fastify, details the header abuse vulnerability, but offers no PoC, exploit, or patch information.

    0000046
    12 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33805 Header Stripping Vulnerability in @fastify/reply-from and @fastif... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33805 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet serves as a brief advisory about a header stripping vulnerability in fastify reply-from, but does not provide details on exploitation, patches, or PoC.

    0000048
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33805: @fastify/reply-from vulnerable t... Fastify proxy bypass lets attackers weaponize Connection headers to strip auth/routing headers added by proxies—classic... https://zerodaysignal.com/vulnerability/CVE-2026-33805 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-33805 has been disclosed as a Fastify proxy bypass that enables attackers to strip authentication headers via crafted Connection headers.

    0000072
    218 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify\/http-proxy-node.js-
Appfastifyreply-from-node.js-

Explore more