PatchSiren

fast-uri CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH fast-uri CVE published 2026-09-03

CVE-2026-84394

The CVE-2026-84394 vulnerability affects the fast-uri library, which accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. This can lead to security bypass in applications that use fast-uri for host validation and make security decisions based on the parsed host. The vulnerability has a high CVSS score of 7.5 and is classified as HIGH severity. Affected appl [truncated]

HIGH fast-uri CVE published 2026-09-02

CVE-2026-84292

fast-uri has a vulnerability where the port component of a URI is not validated during serialization. This can lead to an attacker-controlled host being injected into the authority, potentially allowing for security issues. The vulnerability affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in versions 2.4.6, 3.1.7, and 4.1.4.

HIGH fast-uri CVE published 2026-08-24

CVE-2026-76172

The fast-uri library for Node.js has a vulnerability that allows an attacker to manipulate the scheme component of a URI, potentially leading to off-site redirects, server-side request forgery, or address-policy bypass. This issue arises from a legacy decoding pass over the scheme component and a lack of re-escaping during serialization. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 [truncated]

HIGH fast-uri CVE published 2026-08-24

CVE-2026-75975

The fast-uri library for Node.js has a vulnerability in its custom parser for bracketed IPv6 literals, which does not validate the complete IPv6 grammar. This allows invalid trailing text in an authority to be silently discarded, potentially leading to a server-side request forgery and address-policy bypass primitive. Affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including [truncated]

HIGH fast-uri CVE published 2026-08-24

CVE-2026-75899

The fast-uri library for Node.js has a vulnerability where it decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition. This can lead to a server-side request forgery and host-policy bypass primitive. The affected versions are 2.4.1 up to but not including 2.4.5, 3.1.2 up to but not including 3.1.6, and 4.0.0 up to but not inclu [truncated]

HIGH fast-uri CVE published 2026-07-31

CVE-2026-18446

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T15:16:27.983Z and has not been modified since then. The fast-uri library before versions 4.1.2, 3.1.5, and 2.4.4 has a vulnerability where it requires a literal double forward slash to recognize a URI authority. This can lead to applications using fast-uri for host-based policy enforcement being [truncated]

HIGH fast-uri CVE published 2026-07-19

CVE-2026-16221

CVE-2026-16221 is a vulnerability in fast-uri versions 2.3.1 through 4.1.0 that can lead to incorrect host parsing, potentially allowing attackers to bypass security controls such as allowlists and denylists. This issue arises because fast-uri does not treat the backslash character (U+005C) as an authority delimiter, unlike Node's native WHATWG URL parser. As a result, applications using fast-uri for host [truncated]

HIGH fast-uri CVE published 2026-06-29

CVE-2026-13676

CVE-2026-13676 is a vulnerability in the fast-uri library, which fails to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. This can lead to bypasses in host-based policy checks, such as denylists, loopback filtering, redirect validation, and outbound proxy routing. The vulnerability affects fast-uri versions 2.3.1 through 3.1.2 and 4.0.0. Patches are available in fast-uri 3.1.3 for the 3.x line [truncated]

HIGH fast-uri CVE published 2026-05-04

CVE-2026-6321

A high-severity vulnerability was found in fast-uri, a JavaScript library used for URI parsing. The vulnerability, tracked as CVE-2026-6321, has a CVSS score of 7.5 and is classified as HIGH. The issue arises from the library's handling of percent-encoded path separators and dot segments in its normalize() and equal() functions. This flaw allows attackers to bypass path-based security policies by manipula [truncated]