CVE-2026-85124
Last modified
CVE-2026-85124 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escape the boundary set by the prefix and rewritePrefix options.
Description
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escape the boundary set by the prefix and rewritePrefix options. An unauthenticated network attacker can use this to reach upstream paths that were meant to stay hidden behind the proxy, resulting in disclosure of internal endpoints. This is a path traversal issue (CWE-22). Users should upgrade to @fastify/http-proxy 11.6.2 or later.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| @fastify/http-proxy | @fastify/http-proxy | < 11.6.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-85124?
How severe is CVE-2026-85124?
How do I fix CVE-2026-85124?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-85100A vulnerability was detected in 2FastLabs agent-squad up to …4.3
- CVE-2026-85105A flaw has been found in NousResearch hermes-agent 0.18.0. A…7.3
- CVE-2026-85106A vulnerability has been found in NousResearch hermes-agent …6.3
- CVE-2026-85107A vulnerability was found in NousResearch hermes-agent 0.18.…4.3
- CVE-2026-8511Use after free in UI in Google Chrome prior to 148.0.7778.16…9.6
- CVE-2026-8512Use after free in FileSystem in Google Chrome prior to 148.0…8.3
- CVE-2026-8513Use after free in Input in Google Chrome on Android prior to…8.3
- CVE-2026-8514Use after free in Aura in Google Chrome prior to 148.0.7778.…8.3
- CVE-2026-8515Use after free in HID in Google Chrome prior to 148.0.7778.1…8.3
- CVE-2026-85150A NULL pointer dereference flaw was found in GStreamer's RTS…7.5
- CVE-2026-85154WWBN AVideo contains an authentication failure vulnerability…9.8
- CVE-2026-85155WWBN AVideo contains a SQL injection vulnerability in the so…7.5
Are you affected by CVE-2026-85124?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
