We found results for “”
CVE-2025-66415
Good to know:
Date: December 1, 2025
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Unintended Proxy or Intermediary ('Confused Deputy')
CWE-441Top Fix
Upgrade Version
Upgrade to version @fastify/reply-from - 12.5.0;https://github.com/fastify/fastify-reply-from.git - v12.5.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


