{"id":"CVE-2025-66415","aliases":["GHSA-2q7r-29rg-6m5h"],"url":"https://o3.security/vulnerability/CVE-2025-66415","summary":"fastify-reply-from bypass of reply forwarding","details":"### Summary\nBy crafting a malicious URL, an attacker could access routes that are not allowed, even though the `reply.from` is defined for specific routes in `@fastify/reply-from`.\n\n### Details\n\nAn attacker can bypass the route defined by the `@fastify/reply-from` package by adding a `..` symbol, which, for `curl` version `8.7.1`, is `%2e%2e`.\n\n### Impact\n\nEveryone is using this package with the routes option to protect a 3rd-party resource.","published":"2025-12-01T22:39:32.468Z","modified":"2026-08-12T03:51:14.109462348Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@fastify/reply-from","fixedVersion":"12.5.0"}],"fix":{"url":"https://github.com/fastify/fastify-reply-from/commit/4d9795cd5b57a36756d37b7f036eae369f69fa66","label":"fastify/fastify-reply-from@4d9795c"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66415.json"},{"type":"ADVISORY","url":"https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-2q7r-29rg-6m5h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66415"},{"type":"FIX","url":"https://github.com/fastify/fastify-reply-from/commit/4d9795cd5b57a36756d37b7f036eae369f69fa66"},{"type":"PACKAGE","url":"https://github.com/fastify/fastify-reply-from"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:14.109462348Z"}}