HIGH🇵🇱 Wersja polska

CVE-2026-76172

CVSS 7.5v3.1pub. 2026-08-24upd. 2026-09-02

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encoded slashes parses as a scheme with no authority, so the parsed host and error are both undefined, yet resolving or normalizing that same input emits a network-path reference whose authority is attacker-chosen and re-parses to that host. An application that allowlists on the parsed host, or treats a reference with no authority as safe to resolve against its base, gets the opposite of what it checked, giving an off-site redirect, server-side request forgery, or address-policy bypass. The legacy decoder also expands non-standard escape forms, widening the issue past upstream filters, and control characters in the scheme can reach the output as raw carriage return and line feed. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which reject a scheme that is not valid after decoding. Users should upgrade to a patched version.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • Openjsf Fast Uri

    APP
    Openjsf
    2.3.1 – 2.4.5 (excl.)3.0.0 – 3.1.6 (excl.)4.0.0 – 4.1.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2026-84394HIGH7.5same product

fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error....

CVE-2026-84292HIGH7.5same product

fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the use...

CVE-2026-75899HIGH7.5same product

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes...

CVE-2026-75931HIGH7.5same product

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an...

CVE-2026-75975HIGH7.5same product

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the comp...