Fastify Fastify/forwarded — known CVE vulnerabilities
Every CVE whose affected-product data names Fastify Fastify/forwarded, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (1)
CVE-2026-18174 — CVSS 5.3 (medium): @fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or…