{"id":"CVE-2021-21321","aliases":["GHSA-qmw8-3v4g-gwj4"],"url":"https://o3.security/vulnerability/CVE-2021-21321","summary":"Prefix escape","details":"fastify-reply-from is an npm package which is a fastify plugin to forward the current http request to another server. In fastify-reply-from before version 4.0.2, by crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is \"/pub/\", a user expect that accessing \"/priv\" on the target service would not be possible. In affected versions, it is possible. This is fixed in version 4.0.2.","published":"2021-03-02T04:15:12.487Z","modified":"2026-08-07T17:28:12.862976Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"fastify-reply-from","fixedVersion":"4.0.2"}],"fix":{"url":"https://github.com/fastify/fastify-reply-from/commit/dea227dda606900cc01870d08541b4dcc69d3889","label":"fastify/fastify-reply-from@dea227d"},"references":[{"type":"ADVISORY","url":"https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-qmw8-3v4g-gwj4"},{"type":"ADVISORY","url":"https://www.npmjs.com/package/fastify-reply-from"},{"type":"FIX","url":"https://github.com/fastify/fastify-reply-from/commit/dea227dda606900cc01870d08541b4dcc69d3889"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T17:28:12.862976Z"}}