CVE detail
CVE-2021-21322 — CVE-2021-21322
Published 2021-03-02 · Modified 2026-06-17 · Vendor fastify-http-proxy_project · Product fastify-http-proxy · Source nvd
CRITICAL
severity
CVSS-derived band
0.0161
EPSS probability
exploitation probability, 30d
74.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with hooks. By crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is `/pub/`, a user expect that accessing `/priv` on the target service would not be possible. In affected versions, it is possible. This is fixed in version 4.3.1.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References