CVE-2026-75975High· 7.5▾ TwilightA flaw was found in fast-uri, a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not fully validate the IPv6 grammar, allowing invalid trailing text in an authority to be silently discarded. This can lead to a mal…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
Last analysed / modified upstream
A flaw was found in fast-uri, a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not fully validate the IPv6 grammar, allowing invalid trailing text in an authority to be silently discarded. This can lead to a malformed, attacker-controlled host being normalized into a different, valid IPv6 destination, such as a local or private IPv6 target. An application normalizing untrusted URLs before outbound requests, redirects, or proxy routing could be redirected, resulting in a server-side request forgery (SSRF) and address-policy bypass.
fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization — rated Important by Red Hat. Released 2026-08-24, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before you apply this update, make sure all previously released errata that are relevant to your system are applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67542 Before you apply this update, make sure all previously released errata that are relevant to your system are applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67543 For more about Ansible plugins for Red Hat Developer Hub, see References links https://access.redhat.com/errata/RHSA-2026:65118
Affected packages:
fast-uri >= 2.3.1, < 2.4.5fast-uri >= 3.0.0, < 3.1.6fast-uri >= 4.0.0, < 4.1.3Patched in:
fast-uri 2.4.5fast-uri 3.1.6fast-uri 4.1.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-75899High· 7.5fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)
CVE-2026-76172High· 7.5fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)
CVE-2026-75931High· 7.5fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931)
CVE-2026-67314High· 7.4axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js)
CVE-2026-18446High· 7.5fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446)
CVE-2026-47219High· 7.5find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server (CVE-2026-47219)