PatchSiren cyber security CVE debrief
CVE-2026-84394 fast-uri CVE debrief
The CVE-2026-84394 vulnerability affects the fast-uri library, which accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. This can lead to security bypass in applications that use fast-uri for host validation and make security decisions based on the parsed host. The vulnerability has a high CVSS score of 7.5 and is classified as HIGH severity. Affected applications may be vulnerable to SSRF, redirect, or proxy routing bypass attacks if they use fast-uri for host validation and rely on the parsed host for security decisions. Developers and administrators using fast-uri versions 2.4.5, 3.1.6, or 4.1.3 in applications that perform SSRF denylist checks, redirect allowlisting, or proxy routing based on parsed hosts should be aware of this vulnerability and take steps to mitigate it. The NVD entry is currently Analyzed.
- Vendor
- fast-uri
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-03
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-09-03
- Advisory updated
- 2026-09-04
Who should care
Developers and administrators using fast-uri versions 2.4.5, 3.1.6, or 4.1.3 in applications that perform SSRF denylist checks, redirect allowlisting, or proxy routing based on parsed hosts should be aware of this vulnerability and take steps to mitigate it.
Technical summary
The fast-uri library accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. This can lead to security bypass in applications that use fast-uri for host validation and make security decisions based on the parsed host. The vulnerability affects fast-uri versions 2.4.5, 3.1.6, and 4.1.3, and is fixed in 2.4.6, 3.1.7, and 4.1.4. Affected applications may be vulnerable to SSRF, redirect, or proxy routing bypass attacks if they use fast-uri for host validation and rely on the parsed host for security decisions. Developers and administrators should review and update SSRF denylists, redirect allowlists, and proxy routing configurations to ensure that they are not vulnerable to this attack. The CVE record was published on 2026-09-03T05:16:38.680Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability has a high CVSS score of 7.5 and is classified as HIGH severity. To mitigate this vulnerability, developers and administrators should inventory and verify affected fast-uri versions 2.4.5, 3.1.6, and 4.1.3, apply vendor patches: 2.4.6, 3.1.7, or 4.1.4, and monitor for potential security bypass attempts. Additionally, they should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Finally, they should track exceptions, retest remediated assets, and close the item only after evidence is documented. The official CVE Program record and NIST NVD detail page provide further information on this vulnerability. The vendor advisory also provides guidance on mitigating this vulnerability. By taking these steps, developers and administrators can help prevent security bypass attacks and protect their applications from potential exploitation. The CVE description indicates that fast-uri accepts a host with an unbalanced or misplaced authority bracket without reporting an error. This can lead to security bypass in applications that use fast-uri for host validation and make security decisions based on the parsed host. The vulnerability affects fast-uri versions 2.4.5, 3.1.6
Defensive priority
This vulnerability has a high CVSS score of 7.5 and is classified as HIGH severity. Affected applications may be vulnerable to SSRF, redirect, or proxy routing bypass attacks if they use fast-uri for host validation and rely on the parsed host for security decisions.
Recommended defensive actions
- Inventory and verify affected fast-uri versions 2.4.5, 3.1.6, and 4.1.3
- Apply vendor patches: 2.4.6, 3.1.7, or 4.1.4
- Review and update SSRF denylists, redirect allowlists, and proxy routing configurations
- Monitor for potential security bypass attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE description indicates that fast-uri accepts a host with an unbalanced or misplaced authority bracket without reporting an error. This can lead to security bypass in applications that use fast-uri for host validation and make security decisions based on the parsed host. The vulnerability affects fast-uri versions 2.4.5, 3.1.6, and 4.1.3, and is fixed in 2.4.6, 3.1.7, and 4.1.4.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84394 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84394
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84394 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84394
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.openjsf.org/security-advisories.html
ce714d77-add3-4f53-aff5-83d477b104bb - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g
ce714d77-add3-4f53-aff5-83d477b104bb - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.