CVE-2023-51701: Fastify Reply-From
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with `@fastify/reply-from` could misinterpret the incoming body by passing an header `ContentType: application/json ; charset=utf-8`. This can lead to bypass of security checks. This vulnerability has been patched in '@fastify/reply-from` version 9.6.0.
Affected products
- Fastify Reply-From: before 9.6.0 (fixed in 9.6.0)
Published 2024-01-08. Last modified 2026-06-17.