CVE Explorer
CVE-2026-16117
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, and the prefix-rewrite step uses a literal string replace against the decoded prefix. A request that encodes one or more characters of the configured prefix therefore matches the route but skips the rewrite, so the raw encoded path is forwarded to the ups
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageURL":"pkg:npm/@fastify/http-proxy","product":"@fastify/http-proxy","vendor":"@fastify/http-proxy","versions":[{"lessThan":"11.6.0","status":"affected","version":"0","versionType":"semver"},{"status":"unaffected","version":"11.6.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3d1984a56bff16c0370a54a492817ec3e3c5271b3cd1e1164228e9af3eb045dd · sha256:31c679fac8c64b57… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":10,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3d1984a56bff16c0370a54a492817ec3e3c5271b3cd1e1164228e9af3eb045dd · sha256:31c679fac8c64b57… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3d1984a56bff16c0370a54a492817ec3e3c5271b3cd1e1164228e9af3eb045dd · sha256:31c679fac8c64b57… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://cna.openjsf.org/security-advisories.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3d1984a56bff16c0370a54a492817ec3e3c5271b3cd1e1164228e9af3eb045dd · sha256:31c679fac8c64b57… · /containers/cna/references/1
{"url":"https://github.com/fastify/fastify-http-proxy/security/advisories/GHSA-mx7v-qhg9-2mvv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3d1984a56bff16c0370a54a492817ec3e3c5271b3cd1e1164228e9af3eb045dd · sha256:31c679fac8c64b57… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.