CVE Explorer
CVE-2026-18248
@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and x-apigateway-context HTTP headers before falling back to the trusted internal request token, and those reserved headers are not st
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageURL":"pkg:npm/@fastify/aws-lambda","product":"@fastify/aws-lambda","vendor":"@fastify/aws-lambda","versions":[{"lessThan":"6.4.1","status":"affected","version":"6.4.0","versionType":"semver"},{"status":"unaffected","version":"6.4.1","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5831bf87d14dd88a8beac6e10ccc8d41c1ae3507e7fae4dc0dfa9c44495c4691 · sha256:b0c9b06f173cb75d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5831bf87d14dd88a8beac6e10ccc8d41c1ae3507e7fae4dc0dfa9c44495c4691 · sha256:b0c9b06f173cb75d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5831bf87d14dd88a8beac6e10ccc8d41c1ae3507e7fae4dc0dfa9c44495c4691 · sha256:b0c9b06f173cb75d… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://cna.openjsf.org/security-advisories.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5831bf87d14dd88a8beac6e10ccc8d41c1ae3507e7fae4dc0dfa9c44495c4691 · sha256:b0c9b06f173cb75d… · /containers/cna/references/1
{"url":"https://github.com/fastify/aws-lambda-fastify/security/advisories/GHSA-m93c-jj3f-68ph"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5831bf87d14dd88a8beac6e10ccc8d41c1ae3507e7fae4dc0dfa9c44495c4691 · sha256:b0c9b06f173cb75d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.