
🚨 Moderate-severity security fix in fastify@5.8.3 just released! Patches CVE-2026-3635 — vulnerable to request (protocol and host) spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf
Post summary
Fastify 5.8.3 includes a patch for CVE‑2026‑3635, fixing request spoofing via X‑Forwarded‑Proto/Host under restrictive trustProxy; see the GitHub advisory for details.

