CVE-2026-107318: @fastify/reply-from vulnerable to improper certificate validation in built-in HTTPS transports

Published Oct 8, 2026
·
Updated

@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the proxy does not verify the TLS certificate of the upstream even when the application points it at an https upstream in the default configuration. An on-path network attacker can therefore impersonate the configured HTTPS upstream, read the credentials and request bodies the proxy forwards, and return forged responses that the application trusts. The issue is fixed in @fastify/reply-from 12.7.0, and users should upgrade to 12.7.0 or later. As a workaround, pass an explicit rejectUnauthorized true on the transport, supply an already configured undici instance, or use the undici global agent.

Affected Software

1 affected component
npm/@fastify/reply-from<12.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @fastify/reply-from to a version that resolves this vulnerability.

    Fixed in 12.7.0
  2. Configuration

    Pass an explicit rejectUnauthorized: true on the transport; alternatively, supply an already configured undici instance or use the undici global agent.

    @fastify/reply-from built-in HTTPS transports rejectUnauthorized = true

Event History

Oct 8, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using @fastify/reply-from before 12.7.0 to forward requests to an HTTPS upstream are exposed. The built-in HTTPS transports disable upstream TLS certificate verification even in the default configuration.

2

What does an attacker need to exploit it?

An attacker needs an on-path network position between the proxy and its configured HTTPS upstream. No application privileges or user interaction are required.

3

What could an attacker do if exploitation succeeds?

The attacker can impersonate the HTTPS upstream, read forwarded credentials and request bodies, and send forged responses that the application accepts as trusted.

4

What can be done if upgrading is not immediately possible?

Explicitly set rejectUnauthorized to true on the transport, provide an already configured undici instance, or use the undici global agent. Upgrading to @fastify/reply-from 12.7.0 or later is the documented fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203