Patches: upgrade to @fastify/http-proxy 11.6.0.
Workarounds: none.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastify
Fastify fastify-http-proxy |
|
| Vendors & Products |
Fastify
Fastify fastify-http-proxy |
Mon, 20 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 18 Jul 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapses dot segments, so a crafted upgrade request with path traversal sequences can escape the rewrite prefix and reach upstream endpoints that were not meant to be exposed by the proxy. This is a variant of CVE-2021-21322 in a code path that never went through the HTTP fix in fastify/reply-from. Exploitation requires a non-normalizing WebSocket client, since browsers and the ws package normalize the request path before sending, but raw HTTP clients or downstream proxies that forward the request target unchanged make the attack reachable in production topologies. Patches: upgrade to @fastify/http-proxy 11.6.0. Workarounds: none. | |
| Title | @fastify/http-proxy vulnerable to prefix escape via WebSocket path traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: openjs
Published:
Updated: 2026-07-20T15:15:21.351Z
Reserved: 2026-07-13T17:46:07.876Z
Link: CVE-2026-15631
Updated: 2026-07-20T15:15:16.108Z
Status : Analyzed
Published: 2026-07-18T13:17:05.323
Modified: 2026-07-28T15:42:54.820
Link: CVE-2026-15631
No data.
OpenCVE Enrichment
Updated: 2026-07-30T23:15:06Z