« Volver al listado

CVE-2026-16117

Estado: AnalizadaCrítica (10)—

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, and the prefix-rewrite step uses a literal string replace against the decoded prefix. A request that encodes one or more characters of the configured prefix therefore matches the route but skips the rewrite, so the raw encoded path is forwarded to the upstream unchanged. The upstream then decodes the path and serves it, letting an attacker reach upstream paths that the proxy was configured to hide via rewritePrefix, including internal or administrative endpoints.

Leer descripción completaMostrar menos

Patches: upgrade to @fastify/http-proxy 11.6.0.

Workarounds: none.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad crítica en proxy HTTP (AV:N, PR:N, UI:N) que permite eludir restricciones de prefijo mediante URL-encoding para alcanzar endpoints internos/administrativos ocultos, causando acceso a datos sensibles y potencial manipulación.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-16117",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-16117",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-20T15:14:37.517621Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
      "affectedData": [
        {
          "vendor": "@fastify/http-proxy",
          "product": "@fastify/http-proxy",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "11.6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "11.6.0",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:npm/@fastify/http-proxy",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-18T14:17:11.620",
  "references": [
    {
      "url": "https://cna.openjsf.org/security-advisories.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb"
    },
    {
      "url": "https://github.com/fastify/fastify-http-proxy/security/advisories/GHSA-mx7v-qhg9-2mvv",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ce714d77-add3-4f53-aff5-83d477b104bb",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, and the prefix-rewrite step uses a literal string replace against the decoded prefix. A request that encodes one or more characters of the configured prefix therefore matches the route but skips the rewrite, so the raw encoded path is forwarded to the upstream unchanged. The upstream then decodes the path and serves it, letting an attacker reach upstream paths that the proxy was configured to hide via rewritePrefix, including internal or administrative endpoints.\n\nPatches: upgrade to @fastify/http-proxy 11.6.0.\n\nWorkarounds: none."
    }
  ],
  "lastModified": "2026-07-28T15:39:01.323",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:fastify:fastify\\/http-proxy:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99B92348-B883-46CF-A9B8-24C454F6C2CC",
              "versionEndExcluding": "11.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb"
}