CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-107318: @fastify/reply-from 0 to before 12.7.0

CVE-2026-107318. CVSS 3.1 base score 7.4 (HIGH, Source advisory).

Affected technology

@fastify/reply-from · 0 to before 12.7.0
@fastify/reply-from

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An on-path network attacker can therefore impersonate the configured HTTPS upstream, read the credentials and request bodies the proxy forwards, and return forged responses that the application trusts. Source advisory’s CVSS 3.1 assessment (base score 7.4/10) rates confidentiality and integrity impact as high; availability impact as none.

Published

CWE
CWE-295
CCR priority
29.6 /100 (P4)
CVSS 3.1
7.4 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N · Source advisory
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-107318.html