PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84394 fast-uri CVE debrief

The CVE-2026-84394 vulnerability affects the fast-uri library, which accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. This can lead to security bypass in applications that use fast-uri for host validation and make security decisions based on the parsed host. The vulnerability has a high CVSS score of 7.5 and is classified as HIGH severity. Affected applications may be vulnerable to SSRF, redirect, or proxy routing bypass attacks if they use fast-uri for host validation and rely on the parsed host for security decisions. Developers and administrators using fast-uri versions 2.4.5, 3.1.6, or 4.1.3 in applications that perform SSRF denylist checks, redirect allowlisting, or proxy routing based on parsed hosts should be aware of this vulnerability and take steps to mitigate it. The NVD entry is currently Analyzed.

Vendor
fast-uri
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-03
Original CVE updated
2026-09-04
Advisory published
2026-09-03
Advisory updated
2026-09-04

Who should care

Developers and administrators using fast-uri versions 2.4.5, 3.1.6, or 4.1.3 in applications that perform SSRF denylist checks, redirect allowlisting, or proxy routing based on parsed hosts should be aware of this vulnerability and take steps to mitigate it.

Technical summary

The fast-uri library accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. This can lead to security bypass in applications that use fast-uri for host validation and make security decisions based on the parsed host. The vulnerability affects fast-uri versions 2.4.5, 3.1.6, and 4.1.3, and is fixed in 2.4.6, 3.1.7, and 4.1.4. Affected applications may be vulnerable to SSRF, redirect, or proxy routing bypass attacks if they use fast-uri for host validation and rely on the parsed host for security decisions. Developers and administrators should review and update SSRF denylists, redirect allowlists, and proxy routing configurations to ensure that they are not vulnerable to this attack. The CVE record was published on 2026-09-03T05:16:38.680Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability has a high CVSS score of 7.5 and is classified as HIGH severity. To mitigate this vulnerability, developers and administrators should inventory and verify affected fast-uri versions 2.4.5, 3.1.6, and 4.1.3, apply vendor patches: 2.4.6, 3.1.7, or 4.1.4, and monitor for potential security bypass attempts. Additionally, they should review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Finally, they should track exceptions, retest remediated assets, and close the item only after evidence is documented. The official CVE Program record and NIST NVD detail page provide further information on this vulnerability. The vendor advisory also provides guidance on mitigating this vulnerability. By taking these steps, developers and administrators can help prevent security bypass attacks and protect their applications from potential exploitation. The CVE description indicates that fast-uri accepts a host with an unbalanced or misplaced authority bracket without reporting an error. This can lead to security bypass in applications that use fast-uri for host validation and make security decisions based on the parsed host. The vulnerability affects fast-uri versions 2.4.5, 3.1.6

Defensive priority

This vulnerability has a high CVSS score of 7.5 and is classified as HIGH severity. Affected applications may be vulnerable to SSRF, redirect, or proxy routing bypass attacks if they use fast-uri for host validation and rely on the parsed host for security decisions.

Recommended defensive actions

  • Inventory and verify affected fast-uri versions 2.4.5, 3.1.6, and 4.1.3
  • Apply vendor patches: 2.4.6, 3.1.7, or 4.1.4
  • Review and update SSRF denylists, redirect allowlists, and proxy routing configurations
  • Monitor for potential security bypass attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE description indicates that fast-uri accepts a host with an unbalanced or misplaced authority bracket without reporting an error. This can lead to security bypass in applications that use fast-uri for host validation and make security decisions based on the parsed host. The vulnerability affects fast-uri versions 2.4.5, 3.1.6, and 4.1.3, and is fixed in 2.4.6, 3.1.7, and 4.1.4.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84394 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84394

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84394 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84394

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cna.openjsf.org/security-advisories.html

    ce714d77-add3-4f53-aff5-83d477b104bb - Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/fastify/fast-uri/security/advisories/GHSA-58mr-gqgx-xq4g

    ce714d77-add3-4f53-aff5-83d477b104bb - Mitigation, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.