CVE-2026-3635 impacts Fastify versions up to 5.8.2, allowing an attacker to spoof `request.protocol` and `request.host` values. This vulnerability arises when `trustProxy` is restrictively configured, enabling direct connections from untrusted IPs to manipulate `X-Forwarded-Proto` and `X-Forwarded-Host` headers, bypassing the proxy. Rated Medium with a CVSS score of 6.1 (AV:A/AC:H), it poses a significant risk to applications that use these spoofed values for critical security decisions like HTTPS enforcement or CSRF checks. There is currently no evidence of active exploitation, public exploit code, or significant community attention, and it is not on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 5.8.2CPE match | cpe:2.3:a:fastify:fastify:*:*:*:*:*:node.js:*:* | ||
< 5.8.3CPE matchmatch criteria | cpe:2.3:a:fastify:fastify:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.