fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count — GHSA-3M5P-2C4R-XXW2
GitHub · GitHub · GHSA-3M5P-2C4R-XXW2
ID
GHSA-3M5P-2C4R-XXW2
GHSA-3M5P-2C4R-XXW2
Date
Source
GitHub
GitHub
Vendor
GitHub
GitHub
Threat
medium
medium
CVSS
6.1
6.1
EPSS
0.00144
0.00144
Summary
## Impact The fix for [CVE-2026-3635](https://www.cve.org/CVERecord?id=CVE-2026-3635) ([GHSA-444r-cwp2-x5xf](https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf)) added a `proxyFn(socket.remoteAddress, 0)` guard on the `X-Forwarded-*` reads in `request.host`, `request.protocol`, `request.hostname`, `request.ip`, and `request.ips`. That guard closes the IP, CIDR, and custom-function forms of…
Timeline
- Published by source
- 2026-09-02
Risk context
- Reported severity or threat level: medium.
- Reported CVSS score: 6.1 out of 10.
- Reported EPSS value: 0.00144.
- Review exposure for the affected product or family: npm: fastify.
Product
npm: fastify
What to do
General, cautious steps (verify details in the official source):
- Review exposure and plan remediation based on risk and environment.
- Identify affected product versions in your inventory and verify whether you are impacted.
- Apply vendor patches/updates or recommended mitigations as soon as available.
- Read the official advisory for exact affected versions and remediation steps.
Official advisory
Evidence and provenance
- Canonical advisory ID
- GHSA-3M5P-2C4R-XXW2
- Source
- GitHub
- Vendor
- GitHub
- Published by source
- 2026-09-02
- Last source activity
- 2026-09-02
- Additional identifiers
- CVE-2026-16732
- Curated by
- hlukh.ch
Related advisories and connections
These advisories are connected by shared CVE, product, vendor, source, or time signals.