forward your HTTP request to another server, for fastify
93%
Total Score
98
83
97
100
0
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-247087 New @fastify/reply-from is vulnerable to Confused Deputy in versions 8.3.1 - 12.6.3. | 8.3.1 - 12.6.3 | High |
AIKIDO-2026-659663 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @fastify/reply-from is vulnerable to Denial of Service (DoS) in versions 7.0.0 - 12.6.2. | 7.0.0 - 12.6.2 | Low |
CVE-2026-33805 @fastify/reply-from is vulnerable to Improper Neutralization of HTTP Headers for Scripting Syntax in versions 0.0.0 - 12.6.1. | 0.0.0 - 12.6.1 | High |
CVE-2025-66415 @fastify/reply-from is vulnerable to Unintended Proxy or Intermediary ('Confused Deputy') in versions 0.0.0 - 12.4.0. | 0.0.0 - 12.4.0 | Medium |
CVE-2023-51701 @fastify/reply-from is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 0.0.0 - 9.6.0. | 0.0.0 - 9.6.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
undici Version ^7.0.0 | — | — |
toad-cache Version ^3.7.0 | — | — |
end-of-stream Version ^1.4.4 | — | — |
@fastify/error Version ^4.0.0 | — | — |
fastify-plugin Version ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant