CVE-2026-3635General(fastify / fastify)

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch fastify fastify systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request.protocol and request.host getters read X-Forwarded-Proto and X-Forwarded-Host headers from any connection — including connections from untrusted IPs. This allows an attacker connecting directly to Fastify (bypassing the proxy) to spoof both the protocol and host seen by the application. Affected Versions fastify <= 5.8.2 Impact Applications using request.protocol or request.host for security decisions (HTTPS enforcement, secure cookie flags, CSRF origin checks, URL construction, host-based routing) are affected when trustProxy is configured with a restrictive trust function. When trustProxy: true (trust everything), both host and protocol trust all forwarded headers — this is expected behavior. The vulnerability only manifests with restrictive trust configurations.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-348

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastify

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
fastify

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-23: 2Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 103-23
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Ulises Gascón@kom_256
    Patch

    🚨 Moderate-severity security fix in fastify@5.8.3 just released! Patches CVE-2026-3635 — vulnerable to request (protocol and host) spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf

    Post summary

    Fastify 5.8.3 includes a patch for CVE‑2026‑3635, fixing request spoofing via X‑Forwarded‑Proto/Host under restrictive trustProxy; see the GitHub advisory for details.

    0001096
    5.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3635 Fastify Header Spoofing Vulnerability in Proxy Trust Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3635

    Post summary

    The entry only indicates the CVE identifier and a link to further details, without any specific technical or operational information.

    0000022
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastifyfastify-node.js-

Explore more