Executive brief
@fastify/reply-from is a Fastify plugin that implements reverse proxy functionality. A parsing inconsistency in Content-Type header handling could allow an attacker to bypass security checks by crafting malformed requests with spaces in the Content-Type header (e.g., "application/json ; charset=utf-8"), causing the proxy to misinterpret the request body.
Technical details
This vulnerability is a Content-Type parsing confusion (CWE-444: HTTP Request/Response Smuggling) where @fastify/reply-from does not trim whitespace after splitting the Content-Type header, unlike the main fastify framework which uses fast-content-type-parse for consistent parsing. An attacker can send a crafted Content-Type header with spaces (e.g., "application/json ; charset=utf-8") that will be misinterpreted by the reverse proxy, potentially bypassing downstream security checks. The vulnerability requires only network access with no authentication or user interaction. It is fixed in version 9.6.0 and later.
Affected products
- Fastify @fastify/reply-from <9.6.0
Timeline
- 2024-01-08: disclosed
- 2024-01-08: patched: Fixed in v9.6.0