Junglewise Threat Intelligence

CVE-2026-16117: Fastify @fastify/http-proxy prefix rewrite bypass via URL-encoded characters

CVE-2026-16117 · Severity: critical · CVSS 10 · Published 2026-07-18

Technologies: Fastify Http-Proxy. Vendors: Fastify.

Executive brief

@fastify/http-proxy is a tool used to forward web requests from one server to another, often used to hide internal systems or simplify web addresses. A security flaw allows attackers to bypass path restrictions by using special URL encoding (like using %61 instead of 'a'). This could allow an unauthorized user to access sensitive internal or administrative parts of the backend system that were supposed to be hidden.

Technical details

The vulnerability exists because Fastify's router URL-decodes paths for route matching, but the @fastify/http-proxy plugin uses the original encoded request.url for prefix rewriting. When a request uses percent-encoding (e.g., /%61pi/ instead of /api/), the router matches the route, but the literal string replacement for the prefix fails. Consequently, the raw encoded path is forwarded to the upstream server unchanged. If the upstream server then decodes the path, it may serve internal or administrative endpoints that the proxy was configured to hide via the rewritePrefix option. This is fixed in version 11.6.0.

Affected products

  • Fastify @fastify/http-proxy <= 11.5.0

Timeline

  • 2026-07-18: disclosed
  • 2026-07-18: advisory
  • 2026-07-18: patched

References

Related threats