CVE WATCH / VULNERABILITY DETAIL
CVE-2026-107318
HIGHCVSS 7.4NVD feed
Published 8 October 2026 · tracked since 9 October 2026
Description
@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the proxy does not verify the TLS certificate of the upstream even
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107910 HIGH 8.1
- CVE-2026-107911 HIGH 7.5
- CVE-2026-7826 CRITICAL 9.1
- CVE-2026-7827 HIGH 8.1
- CVE-2026-5759 CRITICAL 9.8
- CVE-2026-107888 MEDIUM 5.1
- CVE-2026-88131 CRITICAL 9.8
- CVE-2026-56857 CRITICAL 9.8
- CVE-2026-107729 MEDIUM 5.5
- CVE-2026-107730 MEDIUM 5.5