VYPR

Fabio

by Fabiolb

Source repositories

CVEs (2)

  • CVE-2025-48865CriMay 30, 2025
    risk 0.52cvss 9.1epss 0.00

    Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except X-Forwarded-For) due to a vulnerability in how it processes hop-by-hop headers. Fabio adds HTTP headers like…

  • CVE-2026-62987MedSep 21, 2026
    risk 0.31cvss 5.8epss 0.00

    Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-configured ClientIPHeader, TLSHeader, and…