Moderate severityNVD Advisory· Published Jan 8, 2024· Updated Jun 3, 2025
@fastify-reply-from JSON Content-Type parsing confusion
CVE-2023-51701
Description
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with @fastify/reply-from could misinterpret the incoming body by passing an header ContentType: application/json ; charset=utf-8. This can lead to bypass of security checks. This vulnerability has been patched in '@fastify/reply-from` version 9.6.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@fastify/reply-fromnpm | < 9.6.0 | 9.6.0 |
Affected products
2- Range: < 9.6.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-v2v2-hph8-q5xpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-51701ghsaADVISORY
- github.com/fastify/fastify-reply-from/commit/cbd7c17c09e6476268e34f5e499a6b923e8acc18ghsaWEB
- github.com/fastify/fastify-reply-from/releases/tag/v9.6.0ghsax_refsource_MISCWEB
- github.com/fastify/fastify-reply-from/security/advisories/GHSA-v2v2-hph8-q5xpghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.