{"id":"CVE-2025-66415","aliases":["GHSA-2q7r-29rg-6m5h"],"url":"https://o3.security/vulnerability/CVE-2025-66415","summary":"fastify-reply-from bypass of reply forwarding","details":"fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.","published":"2025-12-01T22:39:32.468Z","modified":"2026-08-08T03:32:27.035658004Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@fastify/reply-from","fixedVersion":"12.5.0"}],"fix":{"url":"https://github.com/fastify/fastify-reply-from/commit/4d9795cd5b57a36756d37b7f036eae369f69fa66","label":"fastify/fastify-reply-from@4d9795c"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66415.json"},{"type":"ADVISORY","url":"https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-2q7r-29rg-6m5h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66415"},{"type":"FIX","url":"https://github.com/fastify/fastify-reply-from/commit/4d9795cd5b57a36756d37b7f036eae369f69fa66"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:32:27.035658004Z"}}