CVE-2026-75899High· 7.5▾ TwilightA flaw was found in fast-uri, a URI parser for Node.js. The component incorrectly decodes percent escapes in a hostname twice during URI parsing and authority recomposition. This double decoding can allow a remote attacker to manipulate a …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
Last analysed / modified upstream
A flaw was found in fast-uri, a URI parser for Node.js. The component incorrectly decodes percent escapes in a hostname twice during URI parsing and authority recomposition. This double decoding can allow a remote attacker to manipulate a URI to point to a different network destination, such as a loopback address. This vulnerability can lead to Server-Side Request Forgery (SSRF) and bypass host-based security policies.
fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding — rated Important by Red Hat. Released 2026-08-24, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before you apply this update, make sure all previously released errata that are relevant to your system are applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67542 Before you apply this update, make sure all previously released errata that are relevant to your system are applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67543 For more about Ansible plugins for Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:65118
Workarounds / mitigations:
Affected packages:
fast-uri >= 2.4.1, < 2.4.5fast-uri >= 3.1.2, < 3.1.6fast-uri >= 4.0.0, < 4.1.3Patched in:
fast-uri 2.4.5fast-uri 3.1.6fast-uri 4.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-75975High· 7.5fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)
CVE-2026-76172High· 7.5fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)
CVE-2026-75931High· 7.5fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931)
CVE-2026-67314High· 7.4axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js)
CVE-2026-18446High· 7.5fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446)
CVE-2026-47219High· 7.5find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server (CVE-2026-47219)