CVE-2023-51701: Fastify Reply-From

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with `@fastify/reply-from` could misinterpret the incoming body by passing an header `ContentType: application/json ; charset=utf-8`. This can lead to bypass of security checks. This vulnerability has been patched in '@fastify/reply-from` version 9.6.0.

Affected products

  • Fastify Reply-From: before 9.6.0 (fixed in 9.6.0)

Published 2024-01-08. Last modified 2026-06-17.