THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18248 (CRITICAL 9.1) — @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the

[NVD] CVE-2026-18248 (CRITICAL 9.1) — @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the

mednvdPublished 2026-08-03

CVE-2026-18248 CVSS: 9.1 CRITICAL Published: 2026-08-03T16:16:28.247

@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the getter that populates this decoration reads the c

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18248