CVE-2026-18174: @fastify/forwarded vulnerable to improper input validation via unstripped tab characters in X-Forwarded-For

Published Jul 29, 2026
·
Updated

@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or more comma separated entries, the parser trims only space characters and does not strip horizontal tabs, even though RFC 7230 defines optional whitespace as both space and tab. As a result, an entry padded with a tab keeps the literal tab in the resolved address string. Applications that make exact string match security decisions on the resolved client IP, such as an allowlist, a blocklist, a per IP rate limit key, or audit log correlation, can be evaded because the tab corrupted string no longer matches the expected value. This does not cross the trust boundary, since a tab corrupted string is not a valid IP and cannot be mistaken for a trusted proxy. The issue is fixed in @fastify/forwarded 3.0.2.

Affected Software

2 affected components
npm/@fastify/forwarded<3.0.2
fastify Fastify\/forwarded Node.js<3.0.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @fastify/forwarded to a version that resolves this vulnerability.

    Fixed in 3.0.2

Event History

Jul 29, 2026
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-18174?

The severity of CVE-2026-18174 is classified as medium with a score of 5.3.

2

How does CVE-2026-18174 affect systems using @fastify/forwarded?

CVE-2026-18174 affects systems by allowing improper input validation due to unstripped tab characters in X-Forwarded-For headers.

3

What versions are impacted by CVE-2026-18174?

CVE-2026-18174 impacts all versions of @fastify/forwarded prior to 3.0.2.

4

How do I fix CVE-2026-18174?

To fix CVE-2026-18174, update @fastify/forwarded to version 3.0.2 or later.

5

What type of vulnerability is CVE-2026-18174 categorized as?

CVE-2026-18174 is categorized as an Input Validation vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203