GHSA-3m5p-2c4r-xxw2

Suggest an improvement
Source
https://github.com/advisories/GHSA-3m5p-2c4r-xxw2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3m5p-2c4r-xxw2/GHSA-3m5p-2c4r-xxw2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3m5p-2c4r-xxw2
Aliases
Downstream
Published
2026-09-02T15:14:06Z
Modified
2026-09-02T15:30:17Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
Details

Impact

The fix for CVE-2026-3635 (GHSA-444r-cwp2-x5xf) added a proxyFn(socket.remoteAddress, 0) guard on the X-Forwarded-* reads in request.host, request.protocol, request.hostname, request.ip, and request.ips. That guard closes the IP, CIDR, and custom-function forms of trustProxy correctly because those forms compile to predicates that inspect the connecting address. The hop-count form (trustProxy: <number>) compiles to a predicate that structurally ignores the address argument, so the guard reduces to 0 < tp, always true for any tp >= 1.

Applications configured with trustProxy: <number> (documented as "behind N reverse proxies", trustProxy: 1 being the canonical single-proxy setting) remain vulnerable. An attacker who can reach the Fastify origin directly, bypassing the front-facing proxy, can spoof the request fields exactly as in the unpatched version. Impact class matches the parent CVE-2026-3635: host injection in generated URLs, HTTPS-enforcement bypass, secure-cookie / CSRF-origin bypass, host-based routing and cache poisoning.

Patches

Patched in fastify 5.12.1. The numeric form of trustProxy is now disabled at runtime and removed from the TypeScript type union.

Workarounds

  • Migrate to an IP / CIDR / custom-function trustProxy value that validates the connecting address. Custom functions must inspect the address argument, not only the hop index.
  • Ensure the Fastify origin is only reachable through the trusted proxy chain (no direct network path).
Database specific
{
    "cwe_ids": [
        "CWE-348"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-02T15:14:06Z",
    "nvd_published_at": "2026-08-18T21:16:34Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / fastify

Package

Affected ranges

Type
SEMVER
Events
Introduced
5.8.3
Fixed
5.12.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-3m5p-2c4r-xxw2/GHSA-3m5p-2c4r-xxw2.json"