Critical CVE-2026-16117 Vulnerability in @fastify/http-proxy Exposes Internal Endpoints

Critical CVE-2026-16117 Vulnerability in @fastify/http-proxy Exposes Internal Endpoints

First seen 19 Jul 2026, 08:42 UTC cwe.mitre.orgIsmaliciousNvd.Nistcna.openjsf.orgcve.org 91% similarity 70.5

Article Content

Browse articles
ThreatCluster

CVE-2026-16117 was published on July 18, 2026, detailing a critical vulnerability in @fastify/http-proxy versions up to 11.5.0. The flaw allows attackers to bypass request prefix rewrites when the prefix is URL-encoded, potentially exposing internal or administrative endpoints. Fastify's router decodes paths for route matching, but retains the original encoded request.url, leading to a mismatch during the rewrite process. This vulnerability has a CVSS v3 base score of 10, indicating its critical severity. Active exploitation has not been confirmed, and no workarounds are available. Users are advised to upgrade to version 11.6.0 to mitigate the risk. The estimated probability of exploitation in the next 30 days is currently unknown.

Key Points: • CVE-2026-16117 affects @fastify/http-proxy versions up to 11.5.0. • The vulnerability allows attackers to access hidden upstream paths by exploiting URL encoding. • Users should upgrade to @fastify/http-proxy version 11.6.0 to mitigate the risk.

ThreatCluster AI

Timeline

2026-07-18
CVE-2026-16117 published
CVE-2026-16117 was published, detailing a critical vulnerability in @fastify/http-proxy.
Ismalicious
2026-07-19
NVD entry created
NVD published the CVE-2026-16117 entry, confirming the details and impact of the vulnerability.
Nvd.Nist
Recent
No confirmed exploitation
As of the latest reports, there has been no confirmed active exploitation of CVE-2026-16117.
Ismalicious

Community

Browse all →