CVE-2026-107318
Deferred Deferred - Pending Action

Insecure TLS Certificate Verification in @fastify/reply-from

Vulnerability report for CVE-2026-107318, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: openjs

Description

@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the proxy does not verify the TLS certificate of the upstream even when the application points it at an https upstream in the default configuration. An on-path network attacker can therefore impersonate the configured HTTPS upstream, read the credentials and request bodies the proxy forwards, and return forged responses that the application trusts. The issue is fixed in @fastify/reply-from 12.7.0, and users should upgrade to 12.7.0 or later. As a workaround, pass an explicit rejectUnauthorized true on the transport, supply an already configured undici instance, or use the undici global agent.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
@fastify/reply-from @fastify/reply-from 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the @fastify/reply-from plugin before version 12.7.0. It allows HTTPS transports to disable TLS certificate verification by default, setting rejectUnauthorized to false. This means the proxy does not validate the upstream server's TLS certificate, enabling an attacker to impersonate the server, intercept credentials, and manipulate responses.

Detection Guidance

Check if your system uses @fastify/reply-from versions prior to 12.7.0 by running: npm list @fastify/reply-from. If the version is below 12.7.0, the system is vulnerable.

Impact Analysis

An attacker could intercept sensitive data like credentials or request bodies sent through the proxy. They could also return forged responses that the application would trust, potentially leading to data breaches or unauthorized actions. The impact includes loss of confidentiality and integrity of transmitted data.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized data exposure. GDPR requires protection of personal data, and HIPAA mandates secure transmission of health information. The lack of TLS verification violates these requirements, risking legal penalties and loss of trust.

Mitigation Strategies

Upgrade @fastify/reply-from to version 12.7.0 or later using: npm update @fastify/reply-from. Alternatively, configure rejectUnauthorized to true in the transport settings or use an already configured undici instance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107318. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart