Ismalicious
Critical CVE-2026-16117 Vulnerability in @fastify/http-proxy Exposes Internal Endpoints
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
CVE-2026-16117 was published on July 18, 2026, detailing a critical vulnerability in @fastify/http-proxy versions up to 11.5.0. The flaw allows attackers to bypass request prefix rewrites when the prefix is URL-encoded, potentially exposing internal or administrative endpoints. Fastify's router decodes paths for route matching, but retains the original encoded request.url, leading to a mismatch during the rewrite process. This vulnerability has a CVSS v3 base score of 10, indicating its critical severity. Active exploitation has not been confirmed, and no workarounds are available. Users are advised to upgrade to version 11.6.0 to mitigate the risk. The estimated probability of exploitation in the next 30 days is currently unknown.
Key Points: • CVE-2026-16117 affects @fastify/http-proxy versions up to 11.5.0. • The vulnerability allows attackers to access hidden upstream paths by exploiting URL encoding. • Users should upgrade to @fastify/http-proxy version 11.6.0 to mitigate the risk.