Vulnerabilities/

fastify-reply-from affected by bypass of reply forwarding

Severity:
Medium

Description

By crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from.

Recommendation

Update the @fastify/reply-from package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@fastify/reply-from
Anything's wrong? Let us know Last updated on December 02, 2025