CVE-2021-21322
CRITICALFastify-http-proxy < 4.3.1 - Improper Input Validation
Title source: ruleDescription
fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with hooks. By crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is `/pub/`, a user expect that accessing `/priv` on the target service would not be possible. In affected versions, it is possible. This is fixed in version 4.3.1.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_confirm
https://github.com/fastify/fastify-http-proxy/security/advisories/GHSA-c4qr-gmr9-v23w
Product, Third Party Advisory x_refsource_misc
https://www.npmjs.com/package/fastify-http-proxy
Patch, Third Party Advisory x_refsource_misc
https://github.com/fastify/fastify-http-proxy/commit/02d9b43c770aa16bc44470edecfaeb7c17985016
Scores
CVSS v3
10.0
EPSS
0.0019
EPSS Percentile
40.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Details
CWE
CWE-20
Status
published
Products (2)
fastify-http-proxy_project/fastify-http-proxy
< 4.3.1
npm/fastify-http-proxy
0 - 4.3.1npm
Published
Mar 02, 2021
Tracked Since
Feb 18, 2026