« Volver al listado

CVE-2026-3635

Estado: AnalizadaMedia (6.1)—

Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request.protocol and request.host getters read X-Forwarded-Proto and X-Forwarded-Host headers from any connection — including connections from untrusted IPs. This allows an attacker connecting directly to Fastify (bypassing the proxy) to spoof both the protocol and host seen by the application.

Affected Versions fastify <= 5.8.2

Impact Applications using request.protocol or request.host for security decisions (HTTPS enforcement, secure cookie flags, CSRF origin checks, URL construction, host-based routing) are affected when trustProxy is configured with a restrictive trust function.

Leer descripción completaMostrar menos

When trustProxy: true (trust everything), both host and protocol trust all forwarded headers — this is expected behavior. The vulnerability only manifests with restrictive trust configurations.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-3635",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-3635",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-23T15:29:15.532885Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
      "affectedData": [
        {
          "vendor": "fastify",
          "product": "fastify",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "5.8.2"
            },
            {
              "status": "unaffected",
              "version": "5.8.3",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:npm/fastify",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-23T14:16:34.720",
  "references": [
    {
      "url": "https://cna.openjsf.org/security-advisories.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb"
    },
    {
      "url": "https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3635",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
      "description": [
        {
          "lang": "en",
          "value": "CWE-348"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Summary\nWhen trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request.protocol and request.host getters read X-Forwarded-Proto and X-Forwarded-Host headers from any connection — including connections from untrusted IPs. This allows an attacker connecting directly to Fastify (bypassing the proxy) to spoof both the protocol and host seen by the application.\n\nAffected Versions\nfastify <= 5.8.2\n\nImpact\nApplications using request.protocol or request.host for security decisions (HTTPS enforcement, secure cookie flags, CSRF origin checks, URL construction, host-based routing) are affected when trustProxy is configured with a restrictive trust function.\n\nWhen trustProxy: true (trust everything), both host and protocol trust all forwarded headers — this is expected behavior. The vulnerability only manifests with restrictive trust configurations."
    },
    {
      "lang": "es",
      "value": "Resumen\nCuando `trustProxy` se configura con una función de confianza restrictiva (por ejemplo, una IP específica como `trustProxy: '10.0.0.1'`, una subred, un recuento de saltos o una función personalizada), los *getters* `request.protocol` y `request.host` leen los encabezados `X-Forwarded-Proto` y `X-Forwarded-Host` de cualquier conexión, incluidas las conexiones de IPs no confiables. Esto permite a un atacante que se conecta directamente a Fastify (saltándose el proxy) suplantar tanto el protocolo como el *host* vistos por la aplicación.\n\nVersiones Afectadas\nfastify &lt;= 5.8.2\n\nImpacto\nLas aplicaciones que utilizan `request.protocol` o `request.host` para decisiones de seguridad (aplicación de HTTPS, *flags* de cookie seguras, comprobaciones de origen CSRF, construcción de URL, enrutamiento basado en *host*) se ven afectadas cuando `trustProxy` se configura con una función de confianza restrictiva.\n\nCuando `trustProxy: true` (confiar en todo), tanto el *host* como el protocolo confían en todos los encabezados reenviados — este es el comportamiento esperado. La vulnerabilidad solo se manifiesta con configuraciones de confianza restrictivas."
    }
  ],
  "lastModified": "2026-06-17T10:43:54.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:fastify:fastify:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27A424F7-D048-4767-9071-5C4D0A85FDFA",
              "versionEndExcluding": "5.8.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb"
}