Fastify Fastify/http-proxy — known CVE vulnerabilities
Every CVE whose affected-product data names Fastify Fastify/http-proxy, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (3)
CVE-2026-16117 — CVSS 10.0 (critical): Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded…
CVE-2026-15631 — CVSS 8.7 (high): Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against…
CVE-2026-33805 — CVSS 8.6 (high): @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy…